What changed, and why it matters
This commit updates the Skylight Wallet app to work with Monero 0.18.5.3, refreshes several internal library versions, re-enables Linux and Windows release builds, and adds two Android safeguards that prevent other apps or adb commands from launching the wallet directly into specific screens. The Android change appears to close a route-based bypass of the app's lock screen, but the commit message does not call it a security fix and no external advisory is supplied.
Treat this as a routine update with one plausible Android lock-screen bypass fix. Review the monero_c commit 3ca8418f5888883e1bb6e3a6a919260e71a49647 and wallet-core commit 3584c83fc791dfb498dd6a31afb16ebb48b25bf6 changelogs for security-relevant fixes, verify the Android exported-activity behavior on a test device, and consider requesting a CVE only if the route bypass is confirmed exploitable.
Security signals we found
Exported Android MainActivity previously accepted route-bearing intents that could bypass App Lock
New getInitialRoute() and shouldHandleDeeplinking() overrides neutralize route/deep-link injection on Android
Submodule/package bumps to monero_c and wallet-core may include undisclosed security fixes for Monero 0.18.5.3
No CVE, vendor security advisory, or researcher attribution present in the supplied materials
Evidence from the diff
The diff is a routine version bump: monero_c and wallet-core git submodules/packages move to new SHA-pinned commits, release CI re-enables build-linux-x86_64 and build-windows and adds them back to the release job’s needs, and iOS/Android comments are cleaned up. The only functional code change is in MainActivity.kt, which overrides getInitialRoute() to return null and shouldHandleDeeplinking() to return false. The inline comment explains that MainActivity is exported, so any app/adb could previously start it with an intent carrying a route extra or data URI and reach screens past App Lock; the overrides force the app to its own initial route and ignore such intents. The actual security content of the updated monero_c and wallet-core commits is not shown in this diff, so we cannot verify whether they contain additional fixes.
Changed components
Android MainActivity route/deep-link handlingmonero_c native bindings submodulewallet-core Dart packages (wallet_infra, wallet_domain, wallet_monero, wallet_openalias, wallet_background, wallet_fiat, wallet_ui)GitHub Actions release pipeline for Linux x86_64 and Windows x64Inspect captured patch +37 / −29
### .github/workflows/release.yml
@@ -168,7 +168,6 @@ jobs:
build-linux-x86_64:
name: Linux (x86_64)
- if: false # desktop builds disabled for now (also dropped from release job's needs)
runs-on: ubuntu-latest
environment: Release
needs: version
@@ -204,7 +203,6 @@ jobs:
build-windows:
name: Windows (x64)
- if: false # desktop builds disabled for now (also dropped from release job's needs)
runs-on: windows-2022
environment: Release
needs: version
@@ -358,6 +356,8 @@ jobs:
needs:
- version
- build-android
+ - build-linux-x86_64
+ - build-windows
permissions:
contents: write
steps:
### android/app/src/main/kotlin/com/example/monero_light_wallet/MainActivity.kt
@@ -10,14 +10,22 @@ import io.flutter.embedding.engine.FlutterEngine
import io.flutter.plugin.common.MethodChannel
class MainActivity : FlutterFragmentActivity() {
- // App-neutral name shared with wallet-core's SecureClipboard (D10).
+ // App-neutral name shared with wallet-core's SecureClipboard.
private val secureClipboardChannel = "org.magicgrants.wallet/secure_clipboard"
// App-neutral name shared with wallet-core's StoreReview. Which StoreReview
// this resolves to -- Play's review flow or a no-op -- is chosen at build
// time; see build.gradle.kts.
private val storeReviewChannel = "org.magicgrants.wallet/store_review"
+ // MainActivity is exported, so any app (or adb) can start it with an intent
+ // that names a route, via the "route" extra or a data URI, and reach screens
+ // past App Lock. The app takes no links, so ignore both: it always starts at
+ // its own initial route, and a new intent never pushes one.
+ override fun getInitialRoute(): String? = null
+
+ override fun shouldHandleDeeplinking(): Boolean = false
+
override fun configureFlutterEngine(flutterEngine: FlutterEngine) {
super.configureFlutterEngine(flutterEngine)
MethodChannel(flutterEngine.dartExecutor.binaryMessenger, secureClipboardChannel)
### ios/Runner/AppDelegate.swift
@@ -44,7 +44,7 @@ import workmanager_apple
let registrar = engineBridge.pluginRegistry.registrar(forPlugin: "SecureClipboard")
if let messenger = registrar?.messenger() {
- // App-neutral name shared with wallet-core's SecureClipboard (D10).
+ // App-neutral name shared with wallet-core's SecureClipboard.
let channel = FlutterMethodChannel(
name: "org.magicgrants.wallet/secure_clipboard",
binaryMessenger: messenger
### monero_c
@@ -1 +1 @@
-Subproject commit f173c670fef4f67c7b8d1050689a2bd1ddf93a0c
+Subproject commit 3ca8418f5888883e1bb6e3a6a919260e71a49647
### pubspec.lock
@@ -666,8 +666,8 @@ packages:
dependency: "direct main"
description:
path: "impls/monero.dart"
- ref: f173c670fef4f67c7b8d1050689a2bd1ddf93a0c
- resolved-ref: f173c670fef4f67c7b8d1050689a2bd1ddf93a0c
+ ref: "3ca8418f5888883e1bb6e3a6a919260e71a49647"
+ resolved-ref: "3ca8418f5888883e1bb6e3a6a919260e71a49647"
url: "https://github.com/magicgrants/monero_c"
source: git
version: "0.0.0"
@@ -1233,62 +1233,62 @@ packages:
dependency: "direct main"
description:
path: "packages/wallet_background"
- ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
- resolved-ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
+ ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
+ resolved-ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
url: "https://github.com/MAGICGrants/wallet-core"
source: git
version: "0.1.0"
wallet_domain:
dependency: "direct main"
description:
path: "packages/wallet_domain"
- ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
- resolved-ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
+ ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
+ resolved-ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
url: "https://github.com/MAGICGrants/wallet-core"
source: git
version: "0.1.0"
wallet_fiat:
dependency: "direct main"
description:
path: "packages/wallet_fiat"
- ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
- resolved-ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
+ ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
+ resolved-ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
url: "https://github.com/MAGICGrants/wallet-core"
source: git
version: "0.1.0"
wallet_infra:
dependency: "direct main"
description:
path: "packages/wallet_infra"
- ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
- resolved-ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
+ ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
+ resolved-ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
url: "https://github.com/MAGICGrants/wallet-core"
source: git
version: "0.1.0"
wallet_monero:
dependency: "direct main"
description:
path: "packages/wallet_monero"
- ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
- resolved-ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
+ ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
+ resolved-ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
url: "https://github.com/MAGICGrants/wallet-core"
source: git
version: "0.1.0"
wallet_openalias:
dependency: "direct main"
description:
path: "packages/wallet_openalias"
- ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
- resolved-ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
+ ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
+ resolved-ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
url: "https://github.com/MAGICGrants/wallet-core"
source: git
version: "0.1.0"
wallet_ui:
dependency: "direct main"
description:
path: "packages/wallet_ui"
- ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
- resolved-ref: "77c6e66f32b10090c4b06198211f2f54b63f2136"
+ ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
+ resolved-ref: "3584c83fc791dfb498dd6a31afb16ebb48b25bf6"
url: "https://github.com/MAGICGrants/wallet-core"
source: git
version: "0.1.0"
### pubspec.yaml
@@ -57,45 +57,45 @@ dependencies:
monero:
git:
url: https://github.com/magicgrants/monero_c
- ref: f173c670fef4f67c7b8d1050689a2bd1ddf93a0c
+ ref: 3ca8418f5888883e1bb6e3a6a919260e71a49647
path: impls/monero.dart
# wallet-core packages; SHA-pinned for release, redirected to the local sibling
# clone by the gitignored pubspec_overrides.yaml for dev.
wallet_infra:
git:
url: https://github.com/MAGICGrants/wallet-core
- ref: 77c6e66f32b10090c4b06198211f2f54b63f2136
+ ref: 3584c83fc791dfb498dd6a31afb16ebb48b25bf6
path: packages/wallet_infra
wallet_domain:
git:
url: https://github.com/MAGICGrants/wallet-core
- ref: 77c6e66f32b10090c4b06198211f2f54b63f2136
+ ref: 3584c83fc791dfb498dd6a31afb16ebb48b25bf6
path: packages/wallet_domain
wallet_monero:
git:
url: https://github.com/MAGICGrants/wallet-core
- ref: 77c6e66f32b10090c4b06198211f2f54b63f2136
+ ref: 3584c83fc791dfb498dd6a31afb16ebb48b25bf6
path: packages/wallet_monero
wallet_openalias:
git:
url: https://github.com/MAGICGrants/wallet-core
- ref: 77c6e66f32b10090c4b06198211f2f54b63f2136
+ ref: 3584c83fc791dfb498dd6a31afb16ebb48b25bf6
path: packages/wallet_openalias
wallet_background:
git:
url: https://github.com/MAGICGrants/wallet-core
- ref: 77c6e66f32b10090c4b06198211f2f54b63f2136
+ ref: 3584c83fc791dfb498dd6a31afb16ebb48b25bf6
path: packages/wallet_background
wallet_fiat:
git:
url: https://github.com/MAGICGrants/wallet-core
- ref: 77c6e66f32b10090c4b06198211f2f54b63f2136
+ ref: 3584c83fc791dfb498dd6a31afb16ebb48b25bf6
path: packages/wallet_fiat
wallet_ui:
git:
url: https://github.com/MAGICGrants/wallet-core
- ref: 77c6e66f32b10090c4b06198211f2f54b63f2136
+ ref: 3584c83fc791dfb498dd6a31afb16ebb48b25bf6
path: packages/wallet_ui
bip39:Why this scored 46/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.