Integrity Check Vulnerability in Cryptomator for iOS Affects Client-Side Encryption
CVE-2026-32318
7.6HIGH
What is CVE-2026-32318?
Cryptomator for iOS, known for providing client-side encryption for cloud files, has an integrity check vulnerability that allows an attacker to tamper with the vault configuration file. This could lead to a man-in-the-middle attack, as the client would trust endpoints from the vault configuration without verifying their authenticity. Users accessing Hub-backed vaults with affected client versions in environments where the vault.cryptomator file can be modified may be vulnerable to token exfiltration. This concern has been addressed in version 2.8.3.
Affected Version(s)
ios < 2.8.3
