Business Insights
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • August 2023
  • January 2023
  • December 2021
  • July 2021
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019

Categories

  • Business
  • Crypto
  • Economy
  • Finance Expert
  • Forex
  • Invest News
  • Investing
  • Tech
  • Trading
  • Uncategorized
  • Videos
Apply Loan
Money Visa
Advertise Us
Money Visa
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact
Announcing the Trillion Dollar Security Initiative
  • Forex

Security Alert – Mist can be vulnerable when navigating to malicious DApps

  • September 4, 2025
  • Roubens Andy King
Total
0
Shares
0
0
0
Total
0
Shares
Share 0
Tweet 0
Pin it 0

Mist leaks some low level APIs, which Dapps could use to gain access to the computer's file system and read/delete files. This would only affect you if you navigate to an untrusted Dapp that knows about these vulnerabilities and specifically tries to attack users. Upgrading Mist is highly recommended to prevent exposure to attacks.

Affected configurations: All versions of Mist from 0.8.6 and lower. This vulnerability doesn't affect the Ethereum Wallet since it can’t load external DApps.
Likelihood: Medium
Severity: High

Summary

Some Mist API methods were exposed, making it possible for malicious webpages to gain access to a privileged interface that could delete files on the local filesystem or launch registered protocol handlers and obtain sensitive information, such as the user directory or the user's “coinbase”.
Vulnerable exposed mist APIs:

mist.shell

mist.dirname

mist.syncMinimongo

web3.eth.coinbase

is now

null

, if the account is not allowed for the dapp

Solution

Upgrade to the latest version of the Mist Browser. Do not use any previous Mist versions to navigate to any untrusted webpage, or local webpages from unknown origins. The Ethereum Wallet is not affected as it doesn't allow navigation to external pages.
This is a good reminder that Mist is currently only considered for Ethereum App Development and should not be used for end users to navigate on the open web until it has reached at least version 1.0. An external audit of Mist is scheduled for December.

A big thanks goes to @tintinweb for his very useful reproduction app to test the vulnerabilities!

We are also thinking of adding Mist to the bounty program, if you find vulnerabilities or severe bugs please contract us at bounty@ethereum.org


Total
0
Shares
Share 0
Tweet 0
Pin it 0
Roubens Andy King

Previous Article
Biggest Wholesale Supplier 100% Original FMCG Products 90% Off Business Idea 💡 #heavydiscountshorts
  • Videos

Biggest Wholesale Supplier 100% Original FMCG Products 90% Off Business Idea 💡 #heavydiscountshorts

  • September 4, 2025
  • Roubens Andy King
Read More
Next Article
Ethereum Foundation Is Dumping ETH Again, Is This The Top?
  • Crypto

Ethereum Foundation Is Dumping ETH Again, Is This The Top?

  • September 4, 2025
  • Roubens Andy King
Read More
You May Also Like
Crypto Phishing Scams Claim Over  Million in August: Tips to Stay Safe
Read More
  • Forex

Crypto Phishing Scams Claim Over $12 Million in August: Tips to Stay Safe

  • Roubens Andy King
  • September 6, 2025
Security Alert – DoS Vulnerability in the Soft Fork
Read More
  • Forex

Security Alert – DoS Vulnerability in the Soft Fork

  • Roubens Andy King
  • September 6, 2025
Bitcoin Price Vs. BTC Treasury Companies: Interesting 1:4 Ratio Pops Up
Read More
  • Forex

Bitcoin Price Vs. BTC Treasury Companies: Interesting 1:4 Ratio Pops Up

  • Roubens Andy King
  • September 6, 2025
The most widely used Bitcoin strategy, explained
Read More
  • Forex

The most widely used Bitcoin strategy, explained

  • Roubens Andy King
  • September 6, 2025
SUI Price To ? Analyst Predicts Altcoin’s Path To New ATH
Read More
  • Forex

SUI Price To $7? Analyst Predicts Altcoin’s Path To New ATH

  • Roubens Andy King
  • September 6, 2025
Tokenizing Car Reservations Can Open Up A Trillion-Dollar Market
Read More
  • Forex

Tokenizing Car Reservations Can Open Up A Trillion-Dollar Market

  • Roubens Andy King
  • September 6, 2025
Ethereum spot ETFs see second-largest outflow surge ever
Read More
  • Forex

Ethereum spot ETFs see second-largest outflow surge ever

  • Roubens Andy King
  • September 6, 2025
Taylor’s Summer Update | Ethereum Foundation Blog
Read More
  • Forex

Taylor’s Summer Update | Ethereum Foundation Blog

  • Roubens Andy King
  • September 6, 2025

Recent Posts

  • Bitcoin Treasury Purchases Down Amid Record Holdings – What Does This Mean?
  • Crypto Phishing Scams Claim Over $12 Million in August: Tips to Stay Safe
  • Bitcoin Mining Difficulty Reaches New All-Time High
  • Security Alert – DoS Vulnerability in the Soft Fork
  • The Devcon2 site is now live!
Featured Posts
  • Bitcoin Treasury Purchases Down Amid Record Holdings – What Does This Mean? 1
    Bitcoin Treasury Purchases Down Amid Record Holdings – What Does This Mean?
    • September 6, 2025
  • Crypto Phishing Scams Claim Over  Million in August: Tips to Stay Safe 2
    Crypto Phishing Scams Claim Over $12 Million in August: Tips to Stay Safe
    • September 6, 2025
  • Bitcoin Mining Difficulty Reaches New All-Time High 3
    Bitcoin Mining Difficulty Reaches New All-Time High
    • September 6, 2025
  • Security Alert – DoS Vulnerability in the Soft Fork 4
    Security Alert – DoS Vulnerability in the Soft Fork
    • September 6, 2025
  • The Devcon2 site is now live! 5
    The Devcon2 site is now live!
    • September 6, 2025
Recent Posts
  • Bitcoin Price Vs. BTC Treasury Companies: Interesting 1:4 Ratio Pops Up
    Bitcoin Price Vs. BTC Treasury Companies: Interesting 1:4 Ratio Pops Up
    • September 6, 2025
  • Bitcoin (BTC) Doesn’t Cheer Fed Cut Bets. What Next?
    Bitcoin (BTC) Doesn’t Cheer Fed Cut Bets. What Next?
    • September 6, 2025
  • Bitcoin Price Holds Above 0,000—How Weak Job Data Could Fuel Next Wave
    Bitcoin Price Holds Above $110,000—How Weak Job Data Could Fuel Next Wave
    • September 6, 2025
Categories
  • Business (2,057)
  • Crypto (1,539)
  • Economy (120)
  • Finance Expert (1,687)
  • Forex (1,538)
  • Invest News (2,359)
  • Investing (1,482)
  • Tech (2,056)
  • Trading (2,024)
  • Uncategorized (2)
  • Videos (811)

Subscribe

Subscribe now to our newsletter

Money Visa
  • Privacy Policy
  • DMCA
  • Terms of Use
Money & Invest Advices

Input your search keywords and press Enter.