Highlights
Auth Bypass: 3 prior fixes. Scrutinize any change in this area.
src/components/SignMessage/SignMessage.js: most-fixed (7 issues). Treat as high-risk during review.
15 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Signature Verification Bypass: Multiple critical flaws in Schnorr signature validation and public key address derivation allowed signature forgery and address spoofing; these are foundational to all signature-based authorization.
Authentication Bypass: The dApp allowlist and Sign button enablement were repeatedly bypassed, allowing signing for unsupported or spoofed dApps; this is a recurring pattern of incomplete allowlist enforcement.
Signature Verification Bypass: Missing EIP6492 signature production for predeploy contracts could cause signatures to be rejected or verified incorrectly, enabling bypass of signature validation.