It's just a WebView shell. Not Kotlin or something.
Login to reply
Replies (1)
Okay, if so my original thoughts were, while they obv cant extract anything from amber, they could have taken any decrypted data and dms, if they took nip46 session keys, they could used them to Harvest now Decrypt later on any nip46 data.
But if a user auto allowed any amber permissions for the app, it would then have be able to auto sign anything.