A popular JavaScript cryptography library is vulnerable in a way which could allow threat actors to break into user accounts.
Socket’s Threat Research Team has outlined all the details.