PT-2026-26660 · Cryptomator · Cryptomator For Ios

Leekiyoon-Sec

·

Published

2026-03-20

·

Updated

2026-03-22

·

CVE-2026-32318

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cryptomator for iOS versions prior to 2.8.3
Description Cryptomator for iOS provides client-side encryption for files in the cloud. A flaw in integrity checks allows tampering with the vault configuration file, potentially leading to a man-in-the-middle attack during the Hub key loading process. Previously, the client trusted endpoints from the vault configuration without verifying host authenticity, which could allow an attacker to steal authentication tokens by substituting a legitimate authentication endpoint with a malicious API endpoint. The issue impacts users unlocking Hub-backed vaults with vulnerable client versions in environments where an attacker can modify the vault.cryptomator file.
Recommendations Update to version 2.8.3 or later.

Exploit

Fix

UI Misrepresentation of Critical Information

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-32318
GHSA-G7FR-C82R-HM6J

Affected Products

Cryptomator For Ios