Close Menu
    Track all markets on TradingView
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Term And Conditions
    • Disclaimer
    • About us
    • Contact us
    Facebook X (Twitter) Instagram
    WSJ-Crypto
    • Home
    • Bitcoin
    • Ethereum
    • Blockchain
    • Crypto Mining
    • Economy and markets
    WSJ-Crypto
    Home » Caution Ahead: Potential Vulnerabilities in Mist When Accessing Malicious DApps
    Ethereum

    Caution Ahead: Potential Vulnerabilities in Mist When Accessing Malicious DApps

    wsjcryptoBy wsjcrypto19 Febbraio 2025Nessun commento2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Mist exposes several low-level APIs, enabling Dapps to access the computer’s file system and read or delete files. This would pose a risk only if you browse to an untrusted Dapp that is aware of these flaws and actively seeks to exploit users. It is strongly advised to update Mist to mitigate the chances of attack.

    Affected configurations: All iterations of Mist from version 0.8.6 and earlier. This flaw does not impact the Ethereum Wallet as it is unable to load external DApps.
    Likelihood: Medium
    Severity: High

    Summary

    Certain Mist API functions were revealed, allowing malicious websites to access a privileged interface that could delete files from the local file system or initiate registered protocol handlers to retrieve sensitive data, including the user directory or the user’s “coinbase”.
    Vulnerable exposed mist APIs:

    mist.shell

    mist.dirname

    mist.syncMinimongo

    web3.eth.coinbase

    now shows as

    null

    , if the account is not authorized for the dapp

    Solution

    Update to the most recent version of the Mist Browser. Avoid using any prior versions of Mist to access untrusted sites or local webpages from ambiguous origins. The Ethereum Wallet remains unaffected, as it does not permit navigation to external websites.
    This serves as a significant reminder that Mist is currently solely intended for Ethereum App Development and should not be utilized by end users to browse the open web until it reaches at least version 1.0. An external audit for Mist is planned for December.

    A special acknowledgment goes to @tintinweb for his invaluable reproduction application for testing the vulnerabilities!

    We are also considering incorporating Mist into the bounty program; if you discover vulnerabilities or critical bugs, please contact us at bounty@ethereum.org




    Source link

    return a list of comma separated tags from this title: Security Alert - Mist can be vulnerable when navigating to malicious DApps
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    wsjcrypto

    Related Posts

    Bringing Ethereum Back Together as One Chain

    18 Novembre 2025

    Navigating the Future: Insights from Checkpoint #7 – November 2025

    15 Novembre 2025

    Fusaka Mainnet Launch: A New Era for Ethereum Enthusiasts

    6 Novembre 2025

    Countdown to Devconnect: Your Essential Guide for the Next Two Weeks

    4 Novembre 2025
    Add A Comment

    Comments are closed.

    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Top Coins
    # Name Price Changes 24h Market CAPVolumeSupply
    WSJ-Crypto
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Term And Conditions
    • Disclaimer
    • About us
    • Contact us
    ©Copyright 2025 . Designed by WSJ-Crypto

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version