Security Flaw in AliasVault Android Password Manager
CVE-2026-22694
What is CVE-2026-22694?
The AliasVault Android password manager, versions 0.24.0 through 0.25.2, exhibits a vulnerability in the validation of passkey requests. This flaw allowed a malicious application to request passkey responses for websites without proper authorization, undermining user security and privacy. The issue stemmed from inadequate checks on app identity, origin, and relying party ID within the Android credential provider mechanism. The vulnerability has been addressed in version 0.25.3, which enhances the validation process and secures user passkey requests.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
aliasvault >= 0.24.0, < 0.25.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
