CVE-2026-32317

7.6

Cryptomator · Cryptomator for Android

Cryptomator for Android versions prior to 1.12.3 contain an integrity check vulnerability that allows attackers to tamper with vault configurations and potentially exfiltrate authentication tokens.

Executive summary

A critical integrity check flaw in Cryptomator for Android allows attackers to perform man-in-the-middle attacks and steal user authentication tokens.

Vulnerability

The application fails to perform adequate origin validation when loading Hub keys, allowing an authenticated user or attacker who can modify the vault configuration file to force the client to trust malicious API endpoints.

Business impact

The exploitation of this vulnerability could lead to the unauthorized interception of cloud storage authentication tokens, resulting in a complete compromise of the encrypted data stored in the cloud. With a CVSS score of 7.6, this high-severity flaw represents a significant risk to data confidentiality and integrity for users relying on Hub-backed vaults.

Remediation

Immediate Action: Update the Cryptomator for Android application to version 1.12.3 or later immediately via the official app store.

Proactive Monitoring: Review access logs for any unauthorized configuration changes to vault files or unusual authentication requests originating from unexpected API endpoints.

Compensating Controls: Ensure that vault configuration files are stored in secure locations with restricted filesystem permissions to prevent unauthorized tampering by other malicious applications on the device.

Exploitation status

Public Exploit Available: No confirmed public exploit (exploit_available: false).

Analyst recommendation

This vulnerability presents a clear risk to the confidentiality of cloud-stored data by circumventing critical trust mechanisms. Users must prioritize updating to version 1.12.3 to ensure that the client correctly validates endpoints and prevents the loading of malicious API configurations. Failure to apply this update leaves sensitive authentication tokens exposed to potential interception.

Sources