ChipTuner · 4d So this is just an RCE? So even nip46 (bunker) users would have their session keys stolen correct? I don't use amber, but I assume if users relaxed Ditto permissions the RCE would allow carte blanche ... Silberengel @Silberengel 1787202235 Ditto’s bug was arbitrary JavaScript in the app WebView (XSS), not RCE, from which they could drive the app. Including the session keys, but no stealing of the key. 1