Well, you could get the nsec if they aren't using a signer.
Login to reply
Replies (1)
I know nothing about android webview stuff, but I assume the nsec-based signing code was in the native side of the app not inside the JS vm and therefore the XSS shouldn't be able to escape it?