Silberengel · 6d Ditto’s bug was arbitrary JavaScript in the app WebView (XSS), not RCE, from which they could drive the app. Including the session keys, but no stealing of the key. ChipTuner @ChipTuner 1787233296 TY. So anything loading into the JS vm. Interesting the session keys are available to the JS window but nsec is not? 1