Polygon Labs quietly patched two security vulnerabilities across the Austin and Kyoto hard forks on the Polygon proof-of-stake network, with no reported mainnet disruption. The Austin hard fork addressed two issues in the Bor execution client: un-metered L1-to-L2 state-sync events and unbounded TxDependency data. The Kyoto hard fork patched byte-level vulnerabilities in the Heimdall consensus client related to protobuf Any message handling and signature validation. Any validator or node still running pre-fork binaries is now operating outside canonical consensus and must immediately upgrade to Bor v2.10.0 and Heimdall v0.11.0. Both forks were validated on the Amoy testnet before mainnet deployment, and public disclosure followed the successful activation by two days.
Source: Read the original article

