PT-2021-7456 · Keybase · Keybase Client For Ios+1
Published
2021-11-09
·
Updated
2021-11-28
·
CVE-2021-34421
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Keybase Client for Android versions prior to 5.8.0
Keybase Client for iOS versions prior to 5.8.0
Description
The issue arises from the incomplete cleanup of temporary or auxiliary resources, which could allow a remote attacker to disclose protected information. This occurs when the receiving user places the chat session in the background while the sending user explodes messages, leading to the potential disclosure of sensitive information meant to be deleted from the customer's device.
Recommendations
For Keybase Client for Android versions prior to 5.8.0, update to version 5.8.0 or later to resolve the issue.
For Keybase Client for iOS versions prior to 5.8.0, update to version 5.8.0 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keybase Client For Android
Keybase Client For Ios