PT-2021-7456 · Keybase · Keybase Client For Ios+1

Published

2021-11-09

·

Updated

2021-11-28

·

CVE-2021-34421

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keybase Client for Android versions prior to 5.8.0 Keybase Client for iOS versions prior to 5.8.0
Description The issue arises from the incomplete cleanup of temporary or auxiliary resources, which could allow a remote attacker to disclose protected information. This occurs when the receiving user places the chat session in the background while the sending user explodes messages, leading to the potential disclosure of sensitive information meant to be deleted from the customer's device.
Recommendations For Keybase Client for Android versions prior to 5.8.0, update to version 5.8.0 or later to resolve the issue. For Keybase Client for iOS versions prior to 5.8.0, update to version 5.8.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06390
CVE-2021-34421

Affected Products

Keybase Client For Android
Keybase Client For Ios