PT-2026-26660 · Cryptomator · Cryptomator For Ios
Leekiyoon-Sec
·
Published
2026-03-20
·
Updated
2026-03-22
·
CVE-2026-32318
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cryptomator for iOS versions prior to 2.8.3
Description
Cryptomator for iOS provides client-side encryption for files in the cloud. A flaw in integrity checks allows tampering with the vault configuration file, potentially leading to a man-in-the-middle attack during the Hub key loading process. Previously, the client trusted endpoints from the vault configuration without verifying host authenticity, which could allow an attacker to steal authentication tokens by substituting a legitimate authentication endpoint with a malicious API endpoint. The issue impacts users unlocking Hub-backed vaults with vulnerable client versions in environments where an attacker can modify the
vault.cryptomator file.Recommendations
Update to version 2.8.3 or later.
Exploit
Fix
UI Misrepresentation of Critical Information
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cryptomator For Ios