MetaMask Browser (on Android) does not enforce Content-Security-Policy header

Smart devices software vulnerabilities
Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

MetaMask Browser (on Android) does not enforce Content-Security-Policy header

Post by Shane1145 »

This vulnerability occurs because the MetaMask browser on Android fails to enforce CSP headers, leaving it open to potential cross-site scripting (XSS) attacks. Attackers can potentially inject malicious scripts into web pages viewed in the MetaMask browser, increasing the risk of data exposure and security breaches.

https://hackerone.com/reports/1941767
Post Reply