{"api_version":"1","generated_at":"2026-06-27T02:03:22+00:00","cve":"CVE-2021-34421","urls":{"html":"https://cve.report/CVE-2021-34421","api":"https://cve.report/api/cve/CVE-2021-34421.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-34421","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-34421"},"summary":{"title":"CVE-2021-34421","description":"The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.","state":"PUBLIC","assigner":"security@zoom.us","published_at":"2021-11-11 23:15:00","updated_at":"2022-06-28 14:11:00"},"problem_types":["CWE-459"],"metrics":[],"references":[{"url":"https://explore.zoom.us/en/trust/security/security-bulletin","name":"https://explore.zoom.us/en/trust/security/security-bulletin","refsource":"MISC","tags":[],"title":"Security Bulletin | Zoom","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-34421","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-34421","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Olivia O'Hara, John Jackson, Jackson Henry, and Robert Willis","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"34421","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"keybase","cpe5":"keybase","cpe6":"5.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"34421","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"keybase","cpe5":"keybase","cpe6":"5.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-34421","qid":"630749","title":"Keybase Client For Android Exposure of Sensitive Information Vulnerability"},{"cve":"CVE-2021-34421","qid":"630756","title":"Keybase Client For iOS Exposure of Sensitive Information Vulnerability"},{"cve":"CVE-2021-34421","qid":"630793","title":"For Android Vulnerability CVE-2021-34421"},{"cve":"CVE-2021-34421","qid":"630804","title":"For ios Vulnerability CVE-2021-34421"}]},"source_records":{"cve_program":{"CVE_data_meta":{"AKA":"Zoom Communications Inc","ASSIGNER":"security@zoom.us","DATE_PUBLIC":"2021-11-12T17:00:00.000Z","ID":"CVE-2021-34421","STATE":"PUBLIC","TITLE":"Retained exploded messages in Keybase Clients for Android and iOS"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Keybase Client for Android ","version":{"version_data":[{"version_affected":"<","version_value":"5.8.0"}]}},{"product_name":"Keybase Client for iOS","version":{"version_data":[{"version_affected":"<","version_value":"5.8.0"}]}}]},"vendor_name":"Zoom Video Communications Inc"}]}},"credit":[{"lang":"eng","value":"Olivia O'Hara, John Jackson, Jackson Henry, and Robert Willis"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Cleartext Storage of Sensitive Information"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://explore.zoom.us/en/trust/security/security-bulletin","name":"https://explore.zoom.us/en/trust/security/security-bulletin"}]},"source":{"discovery":"USER"}},"nvd":{"publishedDate":"2021-11-11 23:15:00","lastModifiedDate":"2022-06-28 14:11:00","problem_types":["CWE-459"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:keybase:keybase:5.8.0:*:*:*:*:android:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:keybase:keybase:5.8.0:*:*:*:*:iphone_os:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"34421","Ordinal":"209880","Title":"CVE-2021-34421","CVE":"CVE-2021-34421","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"34421","Ordinal":"1","NoteData":"The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"34421","Ordinal":"2","NoteData":"2021-11-11","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"34421","Ordinal":"3","NoteData":"2021-11-11","Type":"Other","Title":"Modified"}]}}}