MetaMask - HackerOne Reports
View on HackerOne8
Total Reports
0
Critical
3
High
3
Medium
2
Low
Bypass parsing of transaction data, users on the phishing site will transfer/approve ERC20 tokens without being alerted
Reported by:
ronnyx2017
|
Disclosed:
Low
Weakness: Improper Input Validation
Bounty: $1000.00
Missing ^ Line Beginner Leads to Origin Spoofing
Reported by:
pkkr
|
Disclosed:
High
Arbitrary file write triggered by deeplink abuse - MetaMask Android
Reported by:
hackerontwowheels
|
Disclosed:
Medium
Weakness: Business Logic Errors
MetaMask Browser URL and Transaction Origin Spoofing - Metamask wallet Android & Metamask wallet iOS
Reported by:
renekroka
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Stored
total Failure of password protection while extracting seed phrase! increases attack surface area for scammers
Reported by:
bug_vs_me
|
Disclosed:
Medium
Weakness: Authentication Bypass Using an Alternate Path or Channel
Bounty: $3500.00
Possible to spoof Origin in "Connected Sites"
Reported by:
renniepak
|
Disclosed:
Low
Weakness: User Interface (UI) Misrepresentation of Critical Information
MetaMask Browser (on Android) does not enforce Content-Security-Policy header
Reported by:
renniepak
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Reflected
Missing Line Terminator on allowedOrigins enables origin spoofing
Reported by:
pkkr
|
Disclosed:
High
Weakness: Improper Access Control - Generic