Keybase · Keybase Desktop Client · CVE-2021-23827
Name of the Vulnerable Software and Affected Versions:
Keybase Desktop Client versions prior to 5.6.0 on Windows and macOS
Keybase Desktop Client versions prior to 5.6.1 on Linux
Description:
The issue allows an attacker to obtain potentially sensitive media, such as private pictures, in the Cache and uploadtemps directories. This occurs because the client fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
Recommendations:
For versions prior to 5.6.0 on Windows and macOS, update to version 5.6.0 or later.
For versions prior to 5.6.1 on Linux, update to version 5.6.1 or later.
As a temporary workaround, consider restricting access to the Cache and uploadtemps directories until a patch is applied.