Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of arbitrary headers. This could be used to steal funds or compromise other kinds of cross-chain applications. This vulnerability is fixed in 15.0.1.
The vulnerability results from incorrect verification of signatures or finality proofs (CWE-347: Improper Verification of Cryptographic Signature and CWE-670: Always-Incorrect Control Flow Implementation). A malicious prover is able to provide crafted data that the verifier incorrectly recognizes as confirmation of finality of arbitrarily chosen block headers. The lack of effective integrity control of this data allows the attacker to manipulate the state perceived by the interoperability protocol.
An attacker can force the verifier to accept false information about the state of the blockchain, which may result in theft of funds or takeover of control over other applications using the cross-chain mechanism.
The ismp-grandpa library should be updated to version 15.0.1, in which the vulnerability has been fixed. Detailed information available in the Hyperbridge project security advisory (GHSA-wwx5-gpgr-vxr7) and in the producer's references.
Crate ismp-grandpa of the Hyperbridge project in versions preceding 15.0.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X