Exclusive: Flaws in Zoom’s Keybase App Kept Chat Images From Being Deleted
ID: 11a77b7f-a84f-54e1-931e-41e348b76bf6
STIX ID: report--11a77b7f-a84f-54e1-931e-41e348b76bf6
Feed Name: Security Ledger
A flaw in Keybase (CVE-2021-23827) caused copied or sent images to remain in a temporary upload folder and an unencrypted cache, allowing recovered images from supposedly deleted end-to-end encrypted chats; Sakura Samurai researchers discovered the issue, reported it to Zoom, which released fixes in Keybase 5.6.0/5.6.1. While not enabling remote compromise, the vulnerability risks sensitive image disclosure to an adversary with local access—especially dangerous for users in repressive environments—and the researchers received a bug bounty for the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
