CVE-2026-32318 Details
Description
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endpoints from the vault config without host authenticity checks, which could allow token exfiltration by mixing a legitimate auth endpoint with a malicious API endpoint. Impacted are users unlocking Hub-backed vaults with affected client versions in environments where an attacker can alter the vault.cryptomator file. This issue has been patched in version 2.8.3.
A vulnerability in Cryptomator for iOS prior to version 2.8.3 allows an attacker to manipulate the vault configuration file. This interference creates a man-in-the-middle vulnerability in the Hub key loading process. The issue arises because the client previously trusted endpoints specified in the vault configuration without verifying the authenticity of the hosts. As a result, there was a risk of token exfiltration by combining a legitimate authentication endpoint with a malicious API endpoint. The vulnerability affects users accessing Hub-backed vaults with versions of the app prior to 2.8.3, in situations where an attacker can modify the 'vault.cryptomator' file.
Users can upgrade to Cryptomator for iOS version 2.8.3 or later, which includes a patch for this vulnerability. If an immediate upgrade is not possible, it is recommended to restrict network access so that Cryptomator can only connect to trusted Hub hosts, and to protect the integrity of the vault configuration file by applying strict file permissions and using trusted sync or storage paths.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
| CWE-354 | Improper Validation of Integrity Check Value | [email protected] |
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | [email protected] |
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cryptomator cryptomator | <= 2.8.2 |
CPE
Remediation
| |
| apple iphone os | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Mar 20, 2026 | New CVE Received | [email protected] |