CVE-2026-32318

Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-backed vaults with affected client versions in environments where an attacker can alter the vault.cryptomator file. This issue has been patched in version 2.8.3.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:35

Type Values Removed Values Added
Summary
  • (es) Cryptomator para iOS ofrece cifrado transparente multiplataforma del lado del cliente para archivos en la nube. Antes de la versión 2.8.3, una vulnerabilidad de verificación de integridad permite a un atacante manipular el archivo de configuración de la bóveda, lo que lleva a una vulnerabilidad de man-in-the-middle en el mecanismo de carga de claves de Hub. Antes de esta corrección, el cliente confiaba en los puntos finales de la configuración de la bóveda sin verificaciones de autenticidad del host, lo que podría permitir la exfiltración de tokens mezclando un punto final de autenticación legítimo con un punto final de API malicioso. Los usuarios afectados son aquellos que desbloquean bóvedas respaldadas por Hub con versiones de cliente afectadas en entornos donde un atacante puede alterar el archivo vault.cryptomator. Este problema ha sido parcheado en la versión 2.8.3.

26 Mar 2026, 13:48

Type Values Removed Values Added
First Time Cryptomator cryptomator
Apple
Cryptomator
Apple iphone Os
CPE cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
References () https://github.com/cryptomator/ios/commit/98c31280304af65c0932eb547d5fe4be2d16929c - () https://github.com/cryptomator/ios/commit/98c31280304af65c0932eb547d5fe4be2d16929c - Patch
References () https://github.com/cryptomator/ios/pull/444 - () https://github.com/cryptomator/ios/pull/444 - Issue Tracking
References () https://github.com/cryptomator/ios/releases/tag/2.8.3 - () https://github.com/cryptomator/ios/releases/tag/2.8.3 - Release Notes
References () https://github.com/cryptomator/ios/security/advisories/GHSA-g7fr-c82r-hm6j - () https://github.com/cryptomator/ios/security/advisories/GHSA-g7fr-c82r-hm6j - Vendor Advisory

20 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 19:16

Updated : 2026-06-17 10:35


NVD link : CVE-2026-32318

Mitre link : CVE-2026-32318

CVE.ORG link : CVE-2026-32318


JSON object : View

Products Affected

apple

  • iphone_os

cryptomator

  • cryptomator
CWE
CWE-346

Origin Validation Error

CWE-354

Improper Validation of Integrity Check Value

CWE-451

User Interface (UI) Misrepresentation of Critical Information

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints