Domain Spoofing Vuln in Status Android Wallet

by hackideiomaton 2/26/24, 6:32 PMwith 1 comments
by hackideiomaton 2/26/24, 6:35 PM

This android wallet has an internal browser and it incorrectly strips www. from hosts. This also affects their permission system, meaning this is the perfect bug to phish users.

They didn't answer multiple mails in 30 days, so it's being disclosed.