Skip to content

Conversation

@Tyschenko
Copy link

@Tyschenko Tyschenko commented Jun 10, 2025

We have a potential spoofing approach: if the website has a child iFrame, this child iFrame can execute a request to your MetaMask wallet (send a message). Currently, we don't have a way to distinguish between messages from the main frame and from the child frame.

We discussed in Slack that for now the easiest solution will be to block requests from child iFrames. Later we can investigate how to display on the UI the origin of the request.

I've replicated the same behaviour on both platforms.

@Tyschenko Tyschenko requested a review from smilingkylan June 10, 2025 13:03
@Tyschenko Tyschenko marked this pull request as ready for review June 17, 2025 15:37
Copy link

@sethkfman sethkfman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Tyschenko Tyschenko merged commit 4ce0284 into main Jul 29, 2025
10 checks passed
@Tyschenko Tyschenko mentioned this pull request Jul 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants