In June 2022, security researchers from SonarSource discovered a critical Cross-Site Scripting (XSS) vulnerability in the open-source code of Proton Mail. This flaw could have allowed attackers to bypass end-to-end encryption to steal decrypted emails and impersonate victims. The Discovery
Analysis of spam and virus filter logs showed no evidence of the exploit being used in the wild by malicious actors. Proton Exploit
After researchers disclosed the bug in June 2022, Proton developed and deployed a fix by early July 2022. In June 2022