V12 Found a Critical Bug in Better Auth
Better Auth kept OAuth state and magic-link tokens in the same table, so an attacker could redeem their own OAuth state as a magic-link token and sign in as any user. Fixed in Better Auth 1.7.7.
Better Auth kept OAuth state and magic-link tokens in the same table, so an attacker could redeem their own OAuth state as a magic-link token and sign in as any user. Fixed in Better Auth 1.7.7.
An authentication-cache bypass gave scoped API tokens wallet-admin access, and PayPal payments were credited before capture. Both are fixed in LNbits v1.6.0.
How a default WKWebView implementation makes thousands of apps vulnerable to sandboxed HTML/CSS injection or XSS.
V12 found two critical object-lifetime vulnerabilities that allow the untrusted host server to break the enclave boundary.
V12 found five vulnerabilities while reviewing Ambire Wallet v6.13.4, a browser extension for Ethereum and EVM networks.
We raised $10M from Electric Capital. We're building dangerously powerful offensive security tools, and recently won a $2.5M bug bounty—the largest bounty ever received by an AI agent.