Alex Gleason · 4d :POLICE: A critical security vuln was fixed in Ditto Android that would allow an attacker to steal your nsec by getting you to tap an evil URL. :wisp_sad: A new version has been released onto Zapstor... ChipTuner @ChipTuner 1787188141 So this is just an RCE? So even nip46 (bunker) users would have their session keys stolen correct? I don't use amber, but I assume if users relaxed Ditto permissions the RCE would allow carte blanche signing? 2