:POLICE: A critical security vuln was fixed in Ditto Android...

Alex Gleason

npub1q3sle0kvfsehgsuexttt3ugjd8xdklxfwwkh559wxckmzddywnws6cd26p

hex

59485f834f439305f3bad68a07fd112c30591bb79a41288861feab886adf2db6

nevent

nevent1qqs9jjzlsd858yc97waddzs8l5gjcvzerwme5sfg3psla2ugdt0jmdsprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsqgc0uhmxycvm5gwvn944c7yfxnnxm0nyh8tt62zhrvtd3xkj8fhg68pgvv

Kind-1 (TextNote)

2026-08-19T21:32:23Z

:POLICE: A critical security vuln was fixed in Ditto Android that would allow an attacker to steal your nsec by getting you to tap an evil URL. :wisp_sad:

A new version has been released onto Zapstore and Google Play. UPDATE DITTO ANDROID IMMEDIATELY. :POLICE: :POLICE: :POLICE:

Ditto on web and iOS are unaffected. The issue only affects Android because it was a problem in the Android link handler. People using Amber are unaffected by nsec theft but should upgrade anyway because the attack is still arbitrary code injection via evil URL.

What does an evil URL look like? It contains JavaScript code inside of the URL. The path was not being escaped properly, so it could break out and run any script. The fixed version completely changes the way native code triggers UI navigation (event-driven) so we never inject JS code into the UI at all anymore.

Huge shout out and thank you to nostr:npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg for connecting me to the team behind https://v12.sh/ who discovered this vuln, and huge shout and and thank you to them for responsibly disclosing it to us. 🙏 They also discovered some other issues we patched in this release, but the evil URL is by far the worst.

原始 JSON

{
  "kind": 1,
  "id": "59485f834f439305f3bad68a07fd112c30591bb79a41288861feab886adf2db6",
  "pubkey": "0461fcbecc4c3374439932d6b8f11269ccdb7cc973ad7a50ae362db135a474dd",
  "created_at": 1787175143,
  "tags": [
    [
      "p",
      "50d94fc2d8580c682b071a542f8b1e31a200b0508bab95a33bef0855df281d63"
    ],
    [
      "emoji",
      "POLICE",
      "https://cdn.betterttv.net/emote/606c8ab7fba15a03df2c94e6/3x.webp"
    ],
    [
      "emoji",
      "wisp_sad",
      "https://i.nostr.build/dv2M2VV149yhqbWy.png"
    ],
    [
      "client",
      "Ditto",
      "31990:781a1527055f74c1f70230f10384609b34548f8ab6a0a6caa74025827f9fdae5:ditto"
    ]
  ],
  "content": ":POLICE: A critical security vuln was fixed in Ditto Android that would allow an attacker to steal your nsec by getting you to tap an evil URL. :wisp_sad:\n\nA new version has been released onto Zapstore and Google Play. UPDATE DITTO ANDROID IMMEDIATELY. :POLICE: :POLICE: :POLICE:\n\nDitto on web and iOS are unaffected. The issue only affects Android because it was a problem in the Android link handler. People using Amber are unaffected by nsec theft but should upgrade anyway because the attack is still arbitrary code injection via evil URL.\n\nWhat does an evil URL look like? It contains JavaScript code inside of the URL. The path was not being escaped properly, so it could break out and run any script. The fixed version completely changes the way native code triggers UI navigation (event-driven) so we never inject JS code into the UI at all anymore.\n\nHuge shout out and thank you to nostr:npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg for connecting me to the team behind https://v12.sh/ who discovered this vuln, and huge shout and and thank you to them for responsibly disclosing it to us. 🙏 They also discovered some other issues we patched in this release, but the evil URL is by far the worst.",
  "sig": "9e82e3f829095685f65043ff50e5968eb0c965343e61e1b15a7d3259675412497a418d5bd7d411dbdce41fc30f17707a75a92c606318917ef7b06f301413e966"
}