CVE-2021-23827
Keybase vulnerability analysis and mitigation

Overview

Keybase Desktop Client before version 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, contained a vulnerability (CVE-2021-23827) that allowed attackers to obtain potentially sensitive media, such as private pictures, from the Cache and uploadtemps directories. The vulnerability was discovered by John Jackson and reported through Keybase's Bug Bounty Program in January 2021 (Sakura Blog, ZDNET).

Technical details

The vulnerability stemmed from the application's failure to effectively clear cached pictures, even after deletion via normal methodology within the client or using the 'Explode message/Explode now' functionality. On Mac machines, the content could be accessed directly by viewing the directory, while on Windows, image file extensions needed to be changed to .png or .jpg to recover the content. The affected directories included '/Users/usernamehere/Library/Caches/Keybase/uploadtemps' on macOS and 'C:\Users\yourusername\AppData\Local\Keybase\uploadtemps' on Windows (Sakura Blog).

Impact

The vulnerability's impact was significant due to Keybase's status as an End-to-End Encryption (EE2E) Communication Application. An attacker with local access to a victim's machine could potentially obtain sensitive data through gathered photos, particularly if the user frequently utilized Keybase. Users who believed they were sending photos that could be cleared later might have unknowingly exposed sensitive data, as the photos remained in the cache even after deletion (Sakura Blog).

Exploitability

The vulnerability required local access to exploit, as an attacker needed to be able to read the user's files to access the Cache and uploadtemps directories. While this limited the scope of the vulnerability, it remained a significant concern for a privacy-focused service (ZDNET).

Mitigation and workarounds

Keybase addressed this vulnerability on January 23, 2021, with the release of version 5.6.0 for Windows and macOS, and version 5.6.1 for Linux. The fix not only resolved the bug but also cleared out all images on clients that should have been previously wiped. Users were advised to update to the latest version of Keybase to ensure any unintentionally cached files were removed (ZDNET).

Community reactions

The vulnerability was reported through Keybase's bug bounty program on HackerOne on January 9, 2021. The researcher was awarded $1,000 for the report. Zoom, which had acquired Keybase in May 2020, issued a statement emphasizing their commitment to privacy and security, and encouraged users to apply current updates or download the latest Keybase software with all security updates (ZDNET).

Additional resources


SourceThis report was generated using AI

Related Keybase vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-34422CRITICAL9
  • Keybase logoKeybase
  • keybase
NoYesNov 11, 2021
CVE-2021-34426HIGH7.8
  • Keybase logoKeybase
  • keybase
NoYesDec 14, 2021
CVE-2021-23827MEDIUM5.5
  • Keybase logoKeybase
  • cpe:2.3:a:keybase:keybase
NoYesFeb 23, 2021
CVE-2021-34421MEDIUM4.3
  • Keybase logoKeybase
  • cpe:2.3:a:keybase:keybase
NoYesNov 11, 2021
CVE-2022-22779LOW3.7
  • Zoom Client logoZoom Client
  • cpe:2.3:a:keybase:keybase
NoYesFeb 09, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management