In reply to @v12sec

V12

@v12sec · Twitter ·

We disclosed our finding on 3 August. We're grateful for how prompt Rabby's team was to acknowledge and fix the bug in less than 24 hours. We also reviewed the patch and confirmed it was effective.

Rabby Wallet

Rabby Wallet

We resolved the vulnerability upon discovery and released an update on August 11. Please ensure your Rabby extension is up to date. The mobile app is unaffected. The conditions required to trigger this vulnerability are extremely limited: 1/ The wallet must be connected to a malicious website. 2/ The user must have manually set their auto-lock timer to specifically 10 minutes (all other timer settings are completely unaffected). No exploits have been detected in the wild.