CVE-2022-32969

MEDIUM

MetaMask <10.11.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in order to support the Restore Session feature, aka the Demonic issue.

Scores

CVSS v3 5.9
EPSS 0.0034
EPSS Percentile 56.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-281
Status published
Products (1)
metamask/metamask < 10.11.3
Published Jun 29, 2022
Tracked Since Feb 18, 2026