QID 630804
QID 630804: For ios Vulnerability CVE-2021-34421
The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-34421 to address this issue and obtain more information.
Vendor References
- CVE-2021-34421 -
nvd.nist.gov/vuln/detail/CVE-2021-34421
CVEs related to QID 630804
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-34421 | iOS |
|