Improve authentication callback for Wallet #40188
Labels
feature/web3/wallet
Integrating Ethereum+ wallet support
OS/Android
Fixes related to Android browser functionality
priority/P2
A bad problem. We might uplift this to the next planned release.
QA Pass - Android ARM
QA/Yes
release-notes/include
security
Milestone
Description
During onboarding process for Brave Wallet the authentication callback does not use its result for a cryptographic operation and this may lead a privileged malicious application to bypass it.
More info: https://github.com/brave/brave-core/security/code-scanning/161
Related to https://github.com/brave/brave-core/pull/24943/files
Update
Fingeprint authentication algorithm went through security review:
The text was updated successfully, but these errors were encountered: