2026-08-14 09:07 UTC
We got our first responsible disclosure report yesterday!
On 32bit builds, it was possible to bypass the client-side PBKDF2 iteration count check by overflowing the parameter :calculator: A malicious or compromised server could therefore capture low-iteration hashes on such builds.
We patched the issue and shipped an update for our Android app within a few hours.
Thank you to the researcher for responsibly disclosing!
Commit with additional information: https://codeberg.org/zeitkapsl/zeitkapsl/commit/dafe030e17fa2d66e84c5bc81af085254043bf17
Replies (0)
No replies.