Business Insights
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • August 2023
  • January 2023
  • December 2021
  • July 2021
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019

Categories

  • Business
  • Crypto
  • Economy
  • Finance Expert
  • Forex
  • Invest News
  • Investing
  • Tech
  • Trading
  • Uncategorized
  • Videos
Apply Loan
Money Visa
Advertise Us
Money Visa
  • Home
  • Crypto
  • Finance Expert
  • Business
  • Invest News
  • Investing
  • Trading
  • Forex
  • Videos
  • Economy
  • Tech
  • Contact
Announcing the Trillion Dollar Security Initiative
  • Forex

Security Alert – Mist can be vulnerable when navigating to malicious DApps

  • September 4, 2025
  • Roubens Andy King
Total
0
Shares
0
0
0
Total
0
Shares
Share 0
Tweet 0
Pin it 0

Mist leaks some low level APIs, which Dapps could use to gain access to the computer's file system and read/delete files. This would only affect you if you navigate to an untrusted Dapp that knows about these vulnerabilities and specifically tries to attack users. Upgrading Mist is highly recommended to prevent exposure to attacks.

Affected configurations: All versions of Mist from 0.8.6 and lower. This vulnerability doesn't affect the Ethereum Wallet since it can’t load external DApps.
Likelihood: Medium
Severity: High

Summary

Some Mist API methods were exposed, making it possible for malicious webpages to gain access to a privileged interface that could delete files on the local filesystem or launch registered protocol handlers and obtain sensitive information, such as the user directory or the user's “coinbase”.
Vulnerable exposed mist APIs:

mist.shell

mist.dirname

mist.syncMinimongo

web3.eth.coinbase

is now

null

, if the account is not allowed for the dapp

Solution

Upgrade to the latest version of the Mist Browser. Do not use any previous Mist versions to navigate to any untrusted webpage, or local webpages from unknown origins. The Ethereum Wallet is not affected as it doesn't allow navigation to external pages.
This is a good reminder that Mist is currently only considered for Ethereum App Development and should not be used for end users to navigate on the open web until it has reached at least version 1.0. An external audit of Mist is scheduled for December.

A big thanks goes to @tintinweb for his very useful reproduction app to test the vulnerabilities!

We are also thinking of adding Mist to the bounty program, if you find vulnerabilities or severe bugs please contract us at bounty@ethereum.org


Total
0
Shares
Share 0
Tweet 0
Pin it 0
Roubens Andy King

Previous Article
Biggest Wholesale Supplier 100% Original FMCG Products 90% Off Business Idea 💡 #heavydiscountshorts
  • Videos

Biggest Wholesale Supplier 100% Original FMCG Products 90% Off Business Idea 💡 #heavydiscountshorts

  • September 4, 2025
  • Roubens Andy King
Read More
Next Article
Ethereum Foundation Is Dumping ETH Again, Is This The Top?
  • Crypto

Ethereum Foundation Is Dumping ETH Again, Is This The Top?

  • September 4, 2025
  • Roubens Andy King
Read More
You May Also Like
VC Roundup: Tokenization, Datachains, and Stablecoins
Read More
  • Forex

VC Roundup: Tokenization, Datachains, and Stablecoins

  • Roubens Andy King
  • September 4, 2025
Grayscale adds options spin to Ethereum with launch of ETCO ETF
Read More
  • Forex

Grayscale adds options spin to Ethereum with launch of ETCO ETF

  • Roubens Andy King
  • September 4, 2025
Cardano Sentiment Crashes To 5-Month Low: Why This Is Bullish
Read More
  • Forex

Cardano Sentiment Crashes To 5-Month Low: Why This Is Bullish

  • Roubens Andy King
  • September 4, 2025
Satlantis Is The Discovery App I’ve Been Looking For My Whole Life
Read More
  • Forex

Satlantis Is The Discovery App I’ve Been Looking For My Whole Life

  • Roubens Andy King
  • September 4, 2025
Bitcoin Price Must Reclaim 2K to End Consolidation, Prevent Crash
Read More
  • Forex

Bitcoin Price Must Reclaim $112K to End Consolidation, Prevent Crash

  • Roubens Andy King
  • September 4, 2025
Bitcoin Market Base Turns Neutral-Bearish As Flows Stay Weak
Read More
  • Forex

Bitcoin Market Base Turns Neutral-Bearish As Flows Stay Weak

  • Roubens Andy King
  • September 4, 2025
Is Bitcoin About to Start Its Next Bear Market?
Read More
  • Forex

Is Bitcoin About to Start Its Next Bear Market?

  • Roubens Andy King
  • September 4, 2025
Bad actors are using Ethereum smart contracts to deploy malware: ReversingLabs
Read More
  • Forex

Bad actors are using Ethereum smart contracts to deploy malware: ReversingLabs

  • Roubens Andy King
  • September 4, 2025

Recent Posts

  • VC Roundup: Tokenization, Datachains, and Stablecoins
  • Dow, S&P 500, Nasdaq rise amid weak ADP jobs data, Miran’s Fed Senate hearing
  • Ethereum price surges as Tom Lee’s BitMine buys $358M ETH
  • Grayscale adds options spin to Ethereum with launch of ETCO ETF
  • Hewlett Packard Enterprise, T Rowe Price, C3.ai, and More
Featured Posts
  • VC Roundup: Tokenization, Datachains, and Stablecoins 1
    VC Roundup: Tokenization, Datachains, and Stablecoins
    • September 4, 2025
  • Dow, S&P 500, Nasdaq rise amid weak ADP jobs data, Miran’s Fed Senate hearing 2
    Dow, S&P 500, Nasdaq rise amid weak ADP jobs data, Miran’s Fed Senate hearing
    • September 4, 2025
  • Ethereum price surges as Tom Lee’s BitMine buys 8M ETH 3
    Ethereum price surges as Tom Lee’s BitMine buys $358M ETH
    • September 4, 2025
  • Grayscale adds options spin to Ethereum with launch of ETCO ETF 4
    Grayscale adds options spin to Ethereum with launch of ETCO ETF
    • September 4, 2025
  • Hewlett Packard Enterprise, T Rowe Price, C3.ai, and More 5
    Hewlett Packard Enterprise, T Rowe Price, C3.ai, and More
    • September 4, 2025
Recent Posts
  • Federal Reserve Board – Federal Reserve Board announces termination of enforcement action with Société Générale S.A. and Société Générale New York Branch
    Federal Reserve Board – Federal Reserve Board announces termination of enforcement action with Société Générale S.A. and Société Générale New York Branch
    • September 4, 2025
  • Ethereum Foundation Is Dumping ETH Again, Is This The Top?
    Ethereum Foundation Is Dumping ETH Again, Is This The Top?
    • September 4, 2025
  • Biggest Wholesale Supplier 100% Original FMCG Products 90% Off Business Idea 💡 #heavydiscountshorts
    Biggest Wholesale Supplier 100% Original FMCG Products 90% Off Business Idea 💡 #heavydiscountshorts
    • September 4, 2025
Categories
  • Business (2,057)
  • Crypto (1,485)
  • Economy (118)
  • Finance Expert (1,687)
  • Forex (1,484)
  • Invest News (2,358)
  • Investing (1,454)
  • Tech (2,056)
  • Trading (2,024)
  • Uncategorized (2)
  • Videos (809)

Subscribe

Subscribe now to our newsletter

Money Visa
  • Privacy Policy
  • DMCA
  • Terms of Use
Money & Invest Advices

Input your search keywords and press Enter.