Hacker News new | ask | show | jobs
Domain Spoofing Vuln in Status Android Wallet (github.com)
3 points by hackideiomat 850 days ago
1 comments

This android wallet has an internal browser and it incorrectly strips www. from hosts. This also affects their permission system, meaning this is the perfect bug to phish users.

They didn't answer multiple mails in 30 days, so it's being disclosed.