Vulnerabilities > CVE-2022-32969 - Improper Preservation of Permissions vulnerability in Metamask

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
metamask
CWE-281

Summary

MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue.

Vulnerable Configurations

Part Description Count
Application
Metamask
1

Common Weakness Enumeration (CWE)