Skip to content

Constraint access of biometry keychain items to currently enrolled user

Low
tobihagemann published GHSA-fmh3-xfw7-38cj Mar 7, 2025

Package

Cryptomator for iOS

Affected versions

<2.0.0-beta9

Patched versions

2.0.0-beta9

Description

Discussion: https://community.cryptomator.org/t/security-issue-with-the-new-cryptomator-2-0-app-faceid-change-doesnt-force-password/8962

The access control for CryptomatorUserPresenceKeychain items should be changed from .biometryAny to .biometryCurrentSet here.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs