Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The APP Allows Taking Screenshots of The Recovery Phrase #257

Open
datonawy opened this issue Sep 17, 2022 · 0 comments
Open

The APP Allows Taking Screenshots of The Recovery Phrase #257

datonawy opened this issue Sep 17, 2022 · 0 comments

Comments

@datonawy
Copy link

Bug Type

Security

Reproduction steps

1- Open your TonHub.
2- Head to Settings then Backup keys.
3- Take a screenshot of the recovery phrase.

Actual result

The APP takes a screenshot with the recovery phrase visible (not black screened).

Expected result

Such a sensitive info should be black screened (such as in the android APP version of wallet.ton.org), this is because other APPs might have access to this screenshot. Or maybe the device has some spyware.

Suggested Severity

Vulnerability

Device

Smartphone (please complete the following information):

  • Device: Redmi Note 7
  • OS: Android 12
  • Version 2.5.2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant