#0x5F

TOCTOU Attack Allows Wallet Drain via Transaction Simulation Spoofing

@purgesubmitted a report toJupiterMay 22, 2026 at 07:52
Severity
INFORMATIONAL
CVSS
6.8CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Vulnerability TypeTime-of-Check to Time-of-Use (TOCTOU)
Assetjupiter-mobile-solana-wallet - Jupiter Mobile iOS App

Description

Steps to Reproduce

Impact

Attachments (6)

Activity

@thibaultclosed the report asInformative
May 22
@thibaultchanged the severity fromcriticaltoinformational
May 22
@raccoonsdisclosed this reportPublic Disclosure
May 22