Control UI TLS Pin Enforcement Bypass in OpenClaw for iOS by OpenClaw
CVE-2026-100551
9CRITICAL
What is CVE-2026-100551?
The OpenClaw for iOS application versions between 2026.7.1 and 2026.8.11 have a vulnerability that allows attackers to bypass TLS pin enforcement in the Control UI. This issue arises because while native connections properly enforce the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews do not. An attacker able to redirect to the same host and port can present a different certificate accepted by the iOS system trust, thus serving a malicious Control UI page. This could lead to the unauthorized extraction of sensitive user credentials, including tokens or passwords, potentially granting the attacker unauthorized operator access to critical Gateway state data.
Affected Version(s)
OpenClaw 2026.7.1 < 2026.8.11
OpenClaw 2026.8.11
