AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 52 Monero

set IME_FLAG_NO_PERSONALIZED_LEARNING for mnemonic words entry textfields

Public commit record

What the developer wrote

Authored by julian

50/100 · Thin
set IME_FLAG_NO_PERSONALIZED_LEARNING for mnemonic words entry textfields
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds a privacy flag to the text boxes where users type their wallet recovery phrase (mnemonic seed words). The flag tells the phone's keyboard not to learn or remember those words for personalized suggestions. Without it, sensitive seed words could be stored in the keyboard's user dictionary or cloud-backed learning models, increasing the risk that someone with access to the keyboard data could recover part of a wallet backup.

Recommended action

Review all other sensitive text inputs (passphrase, password, private key, address note fields) and apply `enableIMEPersonalizedLearning: false` where appropriate. Confirm the flag is honored on different Android keyboards and document any iOS/desktop limitations. Consider adding automated linting or widget tests to prevent regression.

Security signals we found

01

Privacy leak via keyboard personalized learning

02

Sensitive input (mnemonic seed words) exposed to IME/keyboard data

03

Android IME flag hardening

04

Partial patch limited to restore view

Risk score

Why this scored 52/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 10/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.