CVE-2026-32318 describes an integrity check vulnerability in Cryptomator for iOS prior to version 2.8.3, affecting users unlocking Hub-backed vaults. This flaw allows an attacker to tamper with the vault configuration file, leading to a man-in-the-middle vulnerability in the Hub key loading mechanism and potential token exfiltration. Rated Medium with a CVSS score of 5.9, exploitation requires an attacker to alter the vault.cryptomator file and is considered to have high attack complexity, primarily impacting confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.2CPE matchmatch criteria | cpe:2.3:a:cryptomator:cryptomator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.