Security release
Release v4.12.0 ships the coordinated security hardening work after v4.11.1.
Please update as soon as possible. Critical security issues found in earlier versions are fixed in this release. Make sure you are running the latest ADAMANT Messenger build.
Key changes
- Close confirmed stored XSS paths, remove all
v-htmlusage, harden markdown rendering throughSafeHtml, and verify node-supplied public keys against addresses - Upgrade local secret storage and password KDF (versioned scrypt), migrate cryptographic helpers to
@noble/@scure, and enforce strict CSP across PWA, Tor, testnet, Android, and Electron artifacts - Harden Android backup / data-extraction boundaries and FileProvider paths, keep AIP-6 signal messages out of visible chat history, and normalize binary / hex crypto input boundaries
- Fix coin-service sync thresholds so lagging indexers are not treated as available, and correct node minimum-version checks to use semver instead of lexicographic string comparison
Draft Release Notes
🐞 Bug Fixes
- #953 [Bug] Coin services treat lagging indexers as online
↳ PRs: #954 by @metalisk - #955 [Bug] Newest nodes (v0.10.0+) flagged as Unsupported / Outdated API version
↳ PRs: #956 by @al-onyxprotocol
🚀 Tasks
- #928 [Task] Prepare safe ESLint 10 migration without losing import checks
↳ PRs: #964 by @al-onyxprotocol - #929 [Task] Stale direct dependency review and phased replacement plan
↳ PRs: #964 by @al-onyxprotocol - #958 [Composite] Full security audit and coordinated hardening release
↳ PRs: #963 by @adamantmm, #964 by @al-onyxprotocol, #966 by @adamant-al
Downloads
| Platform | File |
|---|---|
| Android | ADAMANT.Messenger-4.12.0-signed.apk |
| macOS (Intel) | ADAMANT.Messenger-4.12.0.dmg |
| macOS (Apple Silicon) | ADAMANT.Messenger-4.12.0-arm64.dmg |
| macOS (Universal) | ADAMANT.Messenger-4.12.0-universal.dmg |
| Windows | ADAMANT.Messenger.Setup.4.12.0.exe |
| Linux | ADAMANT-Messenger-4.12.0.AppImage |
Web / PWA: https://msg.adamant.im