CVE-2026-32318

7.6

Cryptomator · Cryptomator for IOS

Cryptomator for IOS before version 2.8.3 contains an integrity check vulnerability that allows attackers to tamper with vault configurations, leading to potential token exfiltration.

Executive summary

A critical integrity check vulnerability in Cryptomator for IOS allows authenticated attackers to perform man-in-the-middle attacks and exfiltrate authentication tokens.

Vulnerability

This vulnerability involves a failure to validate the origin of vault configuration endpoints, specifically regarding the Hub key loading mechanism. An attacker with the ability to modify the vault.cryptomator configuration file can trick an authenticated user into connecting to a malicious API endpoint, facilitating token exfiltration.

Business impact

The exploitation of this flaw could result in the compromise of sensitive cloud-stored data by enabling unauthorized access to encrypted vaults. Given the CVSS score of 7.6, this vulnerability represents a high risk to data confidentiality and integrity, potentially leading to unauthorized access to enterprise or personal information stored in cloud environments.

Remediation

Immediate Action: Update the Cryptomator for IOS application to version 2.8.3 or later via the Apple App Store to resolve the integrity check flaws.

Proactive Monitoring: Monitor vault access logs for any irregular configuration changes or unexpected connections to non-standard API endpoints.

Compensating Controls: Ensure that vault configuration files are stored in secure, read-only locations where possible, and restrict access to the underlying storage provider to trusted users.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Users and administrators should prioritize updating Cryptomator for IOS to version 2.8.3 immediately to secure the Hub key loading mechanism. Failure to patch leaves vault configurations susceptible to manipulation, which could expose authentication tokens to external parties.

Sources