SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-34421

This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.

MEDIUM 4.3EPSS 0.71%

Does this matter?

Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.

Description

The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
0.71% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-459
Affected
keybase/keybase
Source
security@zoom.us

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.