Junglewise Threat Intelligence

Coinbase Wallet SDK security vulnerability

Severity: info · Published 2025-02-10

Vendors: npm.

Executive brief

Coinbase Wallet SDK is a JavaScript library that enables decentralized applications to connect with mobile cryptocurrency wallets. A security vulnerability in versions 4.0 to 4.2.x has been identified that, while not directly compromising user private keys or funds, poses a security risk requiring immediate patching to version 4.3.0 or later.

Technical details

The vulnerability exists in Coinbase Wallet SDK versions from 4.0.0-beta.0 through 4.2.x (prior to 4.3.0). Although the exact nature of the vulnerability is not disclosed in the advisory, it has been classified as high severity by the vendor. The advisory explicitly states it does not directly affect users' cryptographic keys, smart contracts, or cryptocurrency funds. A patch is available in version 4.3.0 and later. Developers using affected versions should update immediately to mitigate the risk.

Affected products

  • Coinbase Wallet SDK >=4.0.0-beta.0, <4.3.0

Timeline

  • 2025-02-10: disclosed
  • 2025-02-10: patched: Fixed in version 4.3.0

References