What changed, and why it matters
This is a routine version bump from 5.6.1 to 5.6.2 for the Cake Wallet/Monero.com apps. The release notes say it fixes QR scanning and includes UI enhancements and bug fixes. The code changes include a safer way to handle socket write errors, showing the 'scan secret' field only for Litecoin wallet restores, and a small Flutter widget-state fix. There is no clear security vulnerability being patched in the diff itself, and no external security advisory or researcher credit is provided.
Treat as a normal maintenance release. Review the socket error-handling change for correctness, but no immediate security response is indicated. Monitor vendor release notes or future advisories if a security relevance is disclosed later.
Security signals we found
Socket error handling hardening (ProxySocketSecure.write)
Conditional display of restore key field (Litecoin-only scan secret)
Flutter mounted-state guard change in send navigation
Version bump with generic 'Bug fixes' release note
Evidence from the diff
The commit bumps app versions/build numbers and updates release notes. Code changes: (1) cw_core/lib/utils/proxy_socket/secure.dart wraps socket.write in runZonedGuarded to catch both synchronous and asynchronous errors, preventing unhandled async exceptions from the StreamConsumer. (2) wallet_restore_from_keys_form.dart conditionally renders the ‘Scan secret’ input only when wallet type is litecoin. (3) send_card.dart changes a context.mounted check to mounted before popping a navigation route. None of these are explicitly framed as security fixes by the vendor, and no CVE or advisory is referenced.
Changed components
cw_core proxy socket secure implementationwallet restore from keys UIsend card navigation UIAndroid/iOS app versioning scriptsInspect captured patch +36 / −39
diff --git a/assets/text/Monerocom_Release_Notes.txt b/assets/text/Monerocom_Release_Notes.txt
index 978e605d..76b14c4e 100644
--- a/assets/text/Monerocom_Release_Notes.txt
+++ b/assets/text/Monerocom_Release_Notes.txt
@@ -1,6 +1,3 @@
-Improve wallets performance
-Improvements for AnyPay
-Better automatic node switching
-New navbar/tab navigation
-Add Dark and tintable app icons
+Fix QR scanning
+UI enhancements
Bug fixes
\ No newline at end of file
diff --git a/assets/text/Release_Notes.txt b/assets/text/Release_Notes.txt
index 2ee3110d..76b14c4e 100644
--- a/assets/text/Release_Notes.txt
+++ b/assets/text/Release_Notes.txt
@@ -1,10 +1,3 @@
-Improve wallets performance
-Litecoin and MWEB support in Cupcake Android
-Ethereum and EVM chains enhancements
-Improved EVM fee estimation
-Improvements for AnyPay
-Better automatic node switching
-New navbar/tab navigation
-WalletConnect enhancements
-Add Dark and tintable app icons
+Fix QR scanning
+UI enhancements
Bug fixes
\ No newline at end of file
diff --git a/cw_core/lib/utils/proxy_socket/secure.dart b/cw_core/lib/utils/proxy_socket/secure.dart
index b281392c..d35a25a0 100644
--- a/cw_core/lib/utils/proxy_socket/secure.dart
+++ b/cw_core/lib/utils/proxy_socket/secure.dart
@@ -40,16 +40,22 @@ class ProxySocketSecure implements ProxySocket {
@override
void write(String data) {
- try {
- if (isClosed) {
- printV("ProxySocketSecure: write: socket is closed");
- return;
+ runZonedGuarded(() {
+ try {
+ if (isClosed) {
+ printV("ProxySocketSecure: write: socket is closed");
+ return;
+ }
+
+ socket.write(data);
+ } catch (e) {
+ // Catches synchronous errors
+ printV("ProxySocketSecure: write (sync error): $e");
}
- socket.write(data);
- } catch (e) {
- printV("ProxySocketSecure: write: $e");
- return;
- }
+ }, (e, stack) {
+ // Catches asynchronous errors (like the Bad State from the StreamConsumer)
+ printV("ProxySocketSecure: write (async error): $e");
+ });
}
@override
diff --git a/lib/src/screens/restore/wallet_restore_from_keys_form.dart b/lib/src/screens/restore/wallet_restore_from_keys_form.dart
index baa0964f..41c94363 100644
--- a/lib/src/screens/restore/wallet_restore_from_keys_form.dart
+++ b/lib/src/screens/restore/wallet_restore_from_keys_form.dart
@@ -267,14 +267,15 @@ class WalletRestoreFromKeysFormState extends State<WalletRestoreFromKeysForm> {
maxLines: null,
),
),
- Container(
- padding: EdgeInsets.only(top: 20.0),
- child: BaseTextFormField(
- controller: scanSecretController,
- hintText: "Scan secret",
- maxLines: null,
+ if (widget.walletRestoreViewModel.type == WalletType.litecoin)
+ Container(
+ padding: EdgeInsets.only(top: 20.0),
+ child: BaseTextFormField(
+ controller: scanSecretController,
+ hintText: "Scan secret",
+ maxLines: null,
+ ),
),
- ),
Container(
padding: EdgeInsets.only(top: 20.0),
child: BaseTextFormField(
diff --git a/lib/src/screens/send/widgets/send_card.dart b/lib/src/screens/send/widgets/send_card.dart
index df3af561..3a1e0c71 100644
--- a/lib/src/screens/send/widgets/send_card.dart
+++ b/lib/src/screens/send/widgets/send_card.dart
@@ -299,7 +299,7 @@ class SendCardState extends State<SendCard> with AutomaticKeepAliveClientMixin<S
PaymentRequest paymentRequest,
PaymentFlowResult result,
) async {
- if (context.mounted && Navigator.of(context).canPop()) {
+ if (mounted && Navigator.of(context).canPop()) {
Navigator.of(context).pop();
}
diff --git a/scripts/android/app_env.sh b/scripts/android/app_env.sh
index 219f38c2..52d0a504 100644
--- a/scripts/android/app_env.sh
+++ b/scripts/android/app_env.sh
@@ -14,15 +14,15 @@ TYPES=($MONERO_COM $CAKEWALLET)
APP_ANDROID_TYPE=$1
MONERO_COM_NAME="Monero.com"
-MONERO_COM_VERSION="5.6.1"
-MONERO_COM_BUILD_NUMBER=4146
+MONERO_COM_VERSION="5.6.2"
+MONERO_COM_BUILD_NUMBER=4147
MONERO_COM_BUNDLE_ID="com.monero.app"
MONERO_COM_PACKAGE="com.monero.app"
MONERO_COM_SCHEME="monero.com"
CAKEWALLET_NAME="Cake Wallet"
-CAKEWALLET_VERSION="5.6.1"
-CAKEWALLET_BUILD_NUMBER=4292
+CAKEWALLET_VERSION="5.6.2"
+CAKEWALLET_BUILD_NUMBER=4293
CAKEWALLET_BUNDLE_ID="com.cakewallet.cake_wallet"
CAKEWALLET_PACKAGE="com.cakewallet.cake_wallet"
CAKEWALLET_SCHEME="cakewallet"
diff --git a/scripts/ios/app_env.sh b/scripts/ios/app_env.sh
index 87b4bda2..0adc08a2 100644
--- a/scripts/ios/app_env.sh
+++ b/scripts/ios/app_env.sh
@@ -12,13 +12,13 @@ TYPES=($MONERO_COM $CAKEWALLET)
APP_IOS_TYPE=$1
MONERO_COM_NAME="Monero.com"
-MONERO_COM_VERSION="5.6.1"
-MONERO_COM_BUILD_NUMBER=149
+MONERO_COM_VERSION="5.6.2"
+MONERO_COM_BUILD_NUMBER=150
MONERO_COM_BUNDLE_ID="com.cakewallet.monero"
CAKEWALLET_NAME="Cake Wallet"
-CAKEWALLET_VERSION="5.6.1"
-CAKEWALLET_BUILD_NUMBER=355
+CAKEWALLET_VERSION="5.6.2"
+CAKEWALLET_BUILD_NUMBER=356
CAKEWALLET_BUNDLE_ID="com.fotolockr.cakewallet"
Why this scored 26/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.