Integrity Check Vulnerability in Cryptomator for iOS Affects Client-Side Encryption
CVE-2026-32318

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-32318?

Cryptomator for iOS, known for providing client-side encryption for cloud files, has an integrity check vulnerability that allows an attacker to tamper with the vault configuration file. This could lead to a man-in-the-middle attack, as the client would trust endpoints from the vault configuration without verifying their authenticity. Users accessing Hub-backed vaults with affected client versions in environments where the vault.cryptomator file can be modified may be vulnerable to token exfiltration. This concern has been addressed in version 2.8.3.

Affected Version(s)

ios < 2.8.3

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.