Re-added missing confirmation screen in the ECDHSessionKey call #49
tsusanka
announced in
Past Security Issues
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Details
The Trezor Safe 3 returns the ECDHSessionKey without requiring appropriate user interaction, resulting in the omission of address confirmation screens in the user interaction workflow.
Fix
trezor/trezor-firmware#3424
Beta Was this translation helpful? Give feedback.
All reactions