Receive: fix stale subaddress selection after switching accounts
What changed, and why it matters
This is a user-interface bug fix in the Monero wallet's Receive page. When a user switched between accounts, the page could show a label and QR code from one account while the displayed address belonged to another account, because the selected list row was not updated to match the new account. The fix makes sure the selected row and displayed address/label stay in sync. It is a consistency bug, not a cryptographic or network vulnerability.
Treat as a normal bug fix. No urgent security response is indicated. Users should update to a build containing this commit to avoid address/label mismatch when switching accounts. If a security advisory is desired, it should describe the issue as a UI consistency bug rather than a critical vulnerability.
Security signals we found
UI state desynchronization between displayed address and label/QR code
Potential user confusion leading to incorrect payment address being shared
No evidence of memory corruption, remote code execution, or cryptographic weakness
Evidence from the diff
The patch fixes stale state in pages/Receive.qml. Previously, subaddressListView.currentIndex was only reset from -1 to 0, so switching to an account with fewer subaddresses left currentIndex pointing past the valid range. The QR/address was already updated to the new account’s primary address, but the label shown next to it could still come from the old selection. Additionally, onPageCompleted hardcoded index 0 when setting current_address, so after revisiting the page the address could disagree with the selected row’s label. The fix extracts updateSelectedAddressDisplay(), validates currentIndex against numSubaddresses(), and calls the shared sync routine on page load.
Changed components
pages/Receive.qmlMonero GUI Receive pageSubaddress list selection and address display logicInspect captured patch +22 / −20
diff --git a/pages/Receive.qml b/pages/Receive.qml
index 9a36a27..4baa530 100644
--- a/pages/Receive.qml
+++ b/pages/Receive.qml
@@ -61,6 +61,24 @@ Rectangle {
inputDialog.open(appWindow.currentWallet.getSubaddressLabel(appWindow.currentWallet.currentSubaddressAccount, _index))
}
+ function updateSelectedAddressDisplay() {
+ appWindow.current_subaddress_table_index = subaddressListView.currentIndex;
+ appWindow.current_address = appWindow.currentWallet.address(
+ appWindow.currentWallet.currentSubaddressAccount,
+ subaddressListView.currentIndex
+ );
+ if (subaddressListView.currentIndex == 0) {
+ selectedAddressDrescription.text = qsTr("Primary address") + translationManager.emptyString;
+ } else {
+ var selectedAddressLabel = appWindow.currentWallet.getSubaddressLabel(appWindow.currentWallet.currentSubaddressAccount, appWindow.current_subaddress_table_index);
+ if (selectedAddressLabel == "") {
+ selectedAddressDrescription.text = "(" + qsTr("no label") + ")" + translationManager.emptyString
+ } else {
+ selectedAddressDrescription.text = selectedAddressLabel
+ }
+ }
+ }
+
function generateQRCodeString() {
if (pageReceive.state == "PaymentRequest") {
return walletManager.make_uri(appWindow.current_address,
@@ -708,24 +726,7 @@ Rectangle {
}
}
}
- onCurrentItemChanged: {
- // reset global vars
- appWindow.current_subaddress_table_index = subaddressListView.currentIndex;
- appWindow.current_address = appWindow.currentWallet.address(
- appWindow.currentWallet.currentSubaddressAccount,
- subaddressListView.currentIndex
- );
- if (subaddressListView.currentIndex == 0) {
- selectedAddressDrescription.text = qsTr("Primary address") + translationManager.emptyString;
- } else {
- var selectedAddressLabel = appWindow.currentWallet.getSubaddressLabel(appWindow.currentWallet.currentSubaddressAccount, appWindow.current_subaddress_table_index);
- if (selectedAddressLabel == "") {
- selectedAddressDrescription.text = "(" + qsTr("no label") + ")" + translationManager.emptyString
- } else {
- selectedAddressDrescription.text = selectedAddressLabel
- }
- }
- }
+ onCurrentItemChanged: updateSelectedAddressDisplay()
}
}
@@ -773,11 +774,12 @@ Rectangle {
subaddressListView.model = appWindow.currentWallet.subaddressModel;
if (appWindow.currentWallet) {
- appWindow.current_address = appWindow.currentWallet.address(appWindow.currentWallet.currentSubaddressAccount, 0)
appWindow.currentWallet.subaddress.refresh(appWindow.currentWallet.currentSubaddressAccount)
- if (subaddressListView.currentIndex == -1) {
+ var numSubaddresses = appWindow.currentWallet.numSubaddresses(appWindow.currentWallet.currentSubaddressAccount);
+ if (subaddressListView.currentIndex == -1 || subaddressListView.currentIndex >= numSubaddresses) {
subaddressListView.currentIndex = 0;
}
+ updateSelectedAddressDisplay();
}
}
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.