Executive brief
A vulnerability in WatermelonDB, a database tool for mobile and web apps, could allow a malicious user to delete data on iOS devices. By providing specially crafted record identifiers, an attacker can cause the application to delete its own records, potentially making the app unusable. While data can typically be restored by logging out and back in, any unsynchronized local changes may be permanently lost.
Technical details
A SQL injection vulnerability exists in the iOS adapter implementation of WatermelonDB due to insufficient validation of record IDs. When an application uses Watermelon Sync or the low-level 'destroyDeletedRecords' method without sanitizing IDs, an attacker can provide a malicious ID that alters the SQL DELETE query. This allows the attacker to delete arbitrary records from the local SQLite database. The exploit is limited by SQLite's inability to nest INSERT/UPDATE queries within a DELETE statement or execute semicolon-separated queries, preventing full database takeover or data exfiltration. The issue is fixed in versions 0.15.1 and 0.16.2.
Affected products
- Nozbe WatermelonDB < 0.15.1, 0.16.0, 0.16.1
Timeline
- 2020-06-03: disclosed
- 2020-06-03: advisory
- 2020-06-03: patched