Credential Storage Vulnerability in OpenClaw for iOS
CVE-2026-100581
6.8MEDIUM
What is CVE-2026-100581?
OpenClaw for iOS versions prior to 2026.8.11 have a significant security issue where sensitive Gateway credentials are stored in plain text within the App Group UserDefaults instead of the secure device Keychain. This design flaw allows attackers who gain access to unencrypted device backups or the App Group container to easily retrieve valid Gateway tokens and passwords, potentially enabling them to authenticate as legitimate operators and gain unauthorized access.
Affected Version(s)
OpenClaw 0 < 2026.8.11
OpenClaw 2026.8.11
