Proton Exploit < ORIGINAL × Report >

Proton Mail XSS Vulnerability: A Deep Dive into the 2022 Exploit

Ensure you are using the latest version of any Proton applications. Proton Exploit

An attacker would need to send two carefully crafted emails to the target. Proton Mail XSS Vulnerability: A Deep Dive into

After researchers disclosed the bug in June 2022, Proton developed and deployed a fix by early July 2022. Proton Exploit

The attack required a specific sequence of actions to succeed, which limited its real-world viability:

The vulnerability was strictly limited to the web interface; non-web Proton Mail apps (iOS/Android) were never affected. Protecting Your Data