#VU64462 Information disclosure in MetaMask - CVE-2022-32969
Published: June 17, 2022
MetaMask
metamask.io
Description
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to the way how web browsers save contents of non-password input fields to the disk as part of their standard “restore session” system. A local attacker can expose a crypto wallet's secret recovery phrase and steal NFTs and cryptocurrency stored within it.