
Cloud Vulnerability DB
A community-led vulnerabilities database
Keybase Desktop Client before version 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, contained a vulnerability (CVE-2021-23827) that allowed attackers to obtain potentially sensitive media, such as private pictures, from the Cache and uploadtemps directories. The vulnerability was discovered by John Jackson and reported through Keybase's Bug Bounty Program in January 2021 (Sakura Blog, ZDNET).
The vulnerability stemmed from the application's failure to effectively clear cached pictures, even after deletion via normal methodology within the client or using the 'Explode message/Explode now' functionality. On Mac machines, the content could be accessed directly by viewing the directory, while on Windows, image file extensions needed to be changed to .png or .jpg to recover the content. The affected directories included '/Users/usernamehere/Library/Caches/Keybase/uploadtemps' on macOS and 'C:\Users\yourusername\AppData\Local\Keybase\uploadtemps' on Windows (Sakura Blog).
The vulnerability's impact was significant due to Keybase's status as an End-to-End Encryption (EE2E) Communication Application. An attacker with local access to a victim's machine could potentially obtain sensitive data through gathered photos, particularly if the user frequently utilized Keybase. Users who believed they were sending photos that could be cleared later might have unknowingly exposed sensitive data, as the photos remained in the cache even after deletion (Sakura Blog).
The vulnerability required local access to exploit, as an attacker needed to be able to read the user's files to access the Cache and uploadtemps directories. While this limited the scope of the vulnerability, it remained a significant concern for a privacy-focused service (ZDNET).
Keybase addressed this vulnerability on January 23, 2021, with the release of version 5.6.0 for Windows and macOS, and version 5.6.1 for Linux. The fix not only resolved the bug but also cleared out all images on clients that should have been previously wiped. Users were advised to update to the latest version of Keybase to ensure any unintentionally cached files were removed (ZDNET).
The vulnerability was reported through Keybase's bug bounty program on HackerOne on January 9, 2021. The researcher was awarded $1,000 for the report. Zoom, which had acquired Keybase in May 2020, issued a statement emphasizing their commitment to privacy and security, and encouraged users to apply current updates or download the latest Keybase software with all security updates (ZDNET).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."