Lemmy.world Incident and Memmy

https://lemmy.ml/post/1896434

Lemmy.world Incident and Memmy - Lemmy

## Note This information is based off of early reports I have seen. I don’t claim to know the extent to which any damage was done and as such recommend a password reset (two-factor authentication would not be of use if authentication tokens were compromised), but we do know that this was a Javascript injection. ========== With the recent Lemmy.world incident, I’d like to update you all. This vulnerability could not have affected you had you been using only Memmy while browsing. It was a Javascript injection, and as Memmy does not execute any Javascript, there is no attack surface here. The only case where this could have affected you would be if you had been signed in to your account inside of the in-app browser or the default browser and opened one of these posts. That however would not be something with Memmy itself, but rather the accessing of the PWA. Regardless, as we don’t actually know what happened, I’d recommend changing passwords. If any JWTs were compromised during this, regardless of 2FA status these tokens could be used to authenticate with your account. From what I have seen, this was an issue that was limited to Lemmy.world, as supposedly they were running a custom frontend build. Other than that, I don’t know anything else. Also, for the record, there is only one instance in this application where a webview is used, which is when viewing the terms of service which simply loads a local file from the app assets. Any questions, I’ll try to answer them but you’d be better off asking people more knowledgeable about the incident.

Subscribed communities are not showing.
Ugh, glad this is just a bug. I thought I lost all my subs!
You need to sign back in. They invalidated all JWTs because of the incident last night. If you just “Edit Account” and enter your password again, you’ll be fine.

I only have one account so I couldn’t re-enter my password. I could hit “save” on the account info and that would fix it until I closed the app and opened it again, then I would have to do the same thing.

I just deleted the app and redownloaded and that seemed to fix it for good.

Thanks!