Business Insights
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • August 2023
  • January 2023
  • December 2021
  • July 2021
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019

Categories

  • Business
  • Crypto
  • Economy
  • Finance Expert
  • Forex
  • Invest News
  • Investing
  • Tech
  • Trading
  • Uncategorized
  • Videos
Apply Loan
Money Visa
Advertise Us
Money Visa
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact
Announcing the Trillion Dollar Security Initiative
  • Forex

Security alert — Chromium vulnerability affecting Mist Browser Beta

  • August 30, 2025
  • Roubens Andy King
Total
0
Shares
0
0
0
Total
0
Shares
Share 0
Tweet 0
Pin it 0

Due to a Chromium vulnerability affecting all released versions of the Mist Browser Beta v0.9.3 and below, we are issuing this alert warning users not to browse untrusted websites with Mist Browser Beta at this time. Users of “Ethereum Wallet” desktop app are not affected.

Affected configurations: Mist Browser Beta v0.9.3 and below
Likelihood: Medium
Severity: High

Malicious websites can potentially steal your private keys.

As Ethereum Wallet desktop app does not qualify as a browser — it accesses only the local Wallet Dapp — it is not subject to the same category of issues present in Mist. For now, it is recommended to use Ethereum Wallet to manage funds and interact with smart contracts instead.

Mist Browser's vision is to be a complete user-facing bridge to the ethereum blockchain and set of technologies that compose the Web3. The browser paves a significant path for the next Web our ecosystem is proudly building.

Security-wise, making a browser (an app that loads untrusted code) that handles private keys is a challenging task. Over the course of the last year, we have had Cure53 conduct an extensive security audit of Mist, and vastly improved the security of both the Mist browser and the underlying platform, Electron. We've promptly fixed found security issues.

But that is not enough. Security in the browser space is a never-ending battle. The Mist browser is based on Electron, which is based on Chromium. Each new Chromium release fixes numerous security issues.

The layer between Mist and Chromium, Electron, is a project led by GitHub that aims to ease the creation of cross-platform applications using JavaScript. Recently, Electron hasn't kept up to date with Chromium, leading to an increasing potential attack surface as time passes.

A core problem with the current architecture is that any 0-day Chromium vulnerability is several patch-steps away from Mist: first Chromium needs to be patched, then Electron needs to update the Chromium version, and finally, Mist needs to update to the new Electron version.

We're examining how we could deal with Electron's not-so-frequent release schedule, to reduce the gap between Chromium versions we use. From preliminary studies, Brave's Muon (an Electron fork) follows Chromium updates closely and is one potential option. The Brave browser, which also contains a cryptocurrency wallet integration, has a similar threat-model and demands for security as Mist.

An important reminder: Mist is still beta software, and you must treat it as such. The Mist Browser beta is provided on an “as is” and “as available” basis and there are no warranties of any kind, expressed or implied, including, but not limited to, warranties of merchantability or fitness of purpose.
Quick security checklist:

  • Avoid keeping large quantities of ether or tokens in private keys on an online computer. Instead, use a hardware wallet, an offline device or a contract-based solution (preferably a mix of those).
  • Back up your private keys — Cloud services are not the best option to store it.
  • Do not visit untrusted websites with Mist.
  • Do not use Mist on untrusted networks.
  • Keep your day-to-day browser updated.
  • Keep track of your Operating System and anti-virus updates.
  • Learn how to verify file checksums (link).

Lastly, we would like to thank the security researchers that worked hard on reproducing and making invaluable submissions through the Ethereum Bounty program.

If you need further information, get in touch here: mist[at]ethereum dot org.

[We'll update this post as the situation evolves].

@evertonfraga
Mist Team




Total
0
Shares
Share 0
Tweet 0
Pin it 0
Roubens Andy King

Previous Article
‘Everyone was grieving’: Did my wife’s brothers cheat her out of her inheritance? There’s a condo and 0K at stake.
  • Finance Expert

‘Everyone was grieving’: Did my wife’s brothers cheat her out of her inheritance? There’s a condo and $550K at stake.

  • August 30, 2025
  • Roubens Andy King
Read More
Next Article
Devcon3 videos available now! | Ethereum Foundation Blog
  • Crypto

Devcon3 videos available now! | Ethereum Foundation Blog

  • August 30, 2025
  • Roubens Andy King
Read More
You May Also Like
Bitcoin At  Million? Adviser Says Doubters Still Won’t Believe It
Read More
  • Forex

Bitcoin At $10 Million? Adviser Says Doubters Still Won’t Believe It

  • Roubens Andy King
  • August 31, 2025
Crypto ‘Buy The Dip’ Calls Spiking May Be A Warning Sign
Read More
  • Forex

Crypto ‘Buy The Dip’ Calls Spiking May Be A Warning Sign

  • Roubens Andy King
  • August 31, 2025
Metaplanet’s Bitcoin Fundraising Strategy Under Pressure as Stock Drops 54%
Read More
  • Forex

Metaplanet’s Bitcoin Fundraising Strategy Under Pressure as Stock Drops 54%

  • Roubens Andy King
  • August 31, 2025
Geth 1.7 – Megara | Ethereum Foundation Blog
Read More
  • Forex

Geth 1.7 – Megara | Ethereum Foundation Blog

  • Roubens Andy King
  • August 31, 2025
Bitcoin whales rotate into Ether, despite B ETH validator exit queue
Read More
  • Forex

Bitcoin whales rotate into Ether, despite $5B ETH validator exit queue

  • Roubens Andy King
  • August 31, 2025
Bitcoin Price Skepticism Will Remain Into The Millions: Analyst
Read More
  • Forex

Bitcoin Price Skepticism Will Remain Into The Millions: Analyst

  • Roubens Andy King
  • August 31, 2025
Byzantium HF Announcement | Ethereum Foundation Blog
Read More
  • Forex

Byzantium HF Announcement | Ethereum Foundation Blog

  • Roubens Andy King
  • August 30, 2025
BTC’s next stop may be 0K: Will Altcoins Collapse Too?
Read More
  • Forex

BTC’s next stop may be $100K: Will Altcoins Collapse Too?

  • Roubens Andy King
  • August 30, 2025

Recent Posts

  • Solana Investors Cash Out Nearly $1-B As SOL Tests Key Price Level
  • Bitcoin At $10 Million? Adviser Says Doubters Still Won’t Believe It
  • Real estate star Fredrik Eklund says wealthy homebuyers ares splurging on at-home ‘biohacking’: Cold plunges, IV drips, hot tubs, and infrared saunas
  • Apple’s Tim Cook gifted Trump a 24K gold plaque — how to get your share of the highly coveted precious metal
  • Decoupling Is No Longer a Property Hack: What the Courts and IRAS Have Made Clear
Featured Posts
  • Solana Investors Cash Out Nearly -B As SOL Tests Key Price Level 1
    Solana Investors Cash Out Nearly $1-B As SOL Tests Key Price Level
    • August 31, 2025
  • Bitcoin At  Million? Adviser Says Doubters Still Won’t Believe It 2
    Bitcoin At $10 Million? Adviser Says Doubters Still Won’t Believe It
    • August 31, 2025
  • Real estate star Fredrik Eklund says wealthy homebuyers ares splurging on at-home ‘biohacking’: Cold plunges, IV drips, hot tubs, and infrared saunas 3
    Real estate star Fredrik Eklund says wealthy homebuyers ares splurging on at-home ‘biohacking’: Cold plunges, IV drips, hot tubs, and infrared saunas
    • August 31, 2025
  • Apple’s Tim Cook gifted Trump a 24K gold plaque — how to get your share of the highly coveted precious metal 4
    Apple’s Tim Cook gifted Trump a 24K gold plaque — how to get your share of the highly coveted precious metal
    • August 31, 2025
  • Decoupling Is No Longer a Property Hack: What the Courts and IRAS Have Made Clear 5
    Decoupling Is No Longer a Property Hack: What the Courts and IRAS Have Made Clear
    • August 31, 2025
Recent Posts
  • Walmart is selling a 2 bathroom cabinet for  that's 'perfect for extra storage'
    Walmart is selling a $122 bathroom cabinet for $63 that's 'perfect for extra storage'
    • August 31, 2025
  • The Pixel 10 Pro is cheaper than the Pixel 10, at least for me
    The Pixel 10 Pro is cheaper than the Pixel 10, at least for me
    • August 31, 2025
  • Saylor vs. Thiel: Two Different Crypto Bets
    Saylor vs. Thiel: Two Different Crypto Bets
    • August 31, 2025
Categories
  • Business (1,991)
  • Crypto (1,386)
  • Economy (115)
  • Finance Expert (1,644)
  • Forex (1,384)
  • Invest News (2,277)
  • Investing (1,391)
  • Tech (1,975)
  • Trading (1,960)
  • Uncategorized (2)
  • Videos (804)

Subscribe

Subscribe now to our newsletter

Money Visa
  • Privacy Policy
  • DMCA
  • Terms of Use
Money & Invest Advices

Input your search keywords and press Enter.