Zurück zum Sicherheitsportal
XSS in Trezor Connect
Gemeldet auf August 3, 2020
In August 2020, we were contacted by Gamer7112, a security researcher, who reported XSS issues in Trezor Connect. The issues were fixed and deployed to production shortly after.
Trezor Connect
Behobene Sicherheitslücken
Gemeldet durch Community. Untersucht. Gelöst. Weil deine Sicherheit nie optional ist.
- Inability to cancel certain flows on pre-production firmware31. Oktober 2025
- Donjon's Trezor Safe 3 evaluation12. November 2024
- Missing confirmation in the ECDHSessionKey call26. November 2023
- XSS in Trezor Connect legacy versions7. Februar 2023
- Insufficient field size check in Protobuf12. Juli 2021
- Missing path isolation check14. Juli 2020