Executive brief
A security flaw in the Matrix JavaScript SDK, used by popular messaging apps like Element and Cinny, could allow a malicious server administrator to intercept private, encrypted messages. By exploiting a logic error in how encryption keys are shared between devices, an attacker who controls a participating server or a user's account can trick a victim's app into handing over the keys needed to read past conversations. This undermines the core privacy guarantee of end-to-end encryption for affected users.
Technical details
A logic error exists in the room key sharing functionality of matrix-js-sdk before version 12.4.1. The vulnerability stems from inadequate identity verification during the key re-sharing process (CWE-322/CWE-290), where the SDK fails to properly verify the target device key. A malicious Matrix homeserver participating in an encrypted room, or an attacker with access to a recipient's account, can send crafted protocol messages to trick a victim's client into disclosing E2EE keys for messages previously sent by that client. This allows the attacker to decrypt end-to-end encrypted communications. The issue is fixed in matrix-js-sdk v12.4.1 by ensuring target device keys are verified on reshare.
Affected products
- Matrix.org matrix-js-sdk < 12.4.1
- Element Element Web <= 1.8.2
- Element Element Desktop <= 1.8.2
- SchildiChat SchildiChat Web <= 1.7.32-sc1
- SchildiChat SchildiChat Desktop <= 1.7.32-sc1
- Cinny Cinny <= 1.2.0
Timeline
- 2021-09-13: patched: v12.4.1 released
- 2021-09-13: advisory: Vendor blog post disclosure
- 2021-09-14: disclosed: GitHub Advisory published
References
- https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-23cm-x6j7-6hq3
- https://github.com/matrix-org/matrix-js-sdk/commit/894c24880da0e1cc81818f51c0db80e3c9fb2be9
- https://github.com/matrix-org/matrix-js-sdk
- https://github.com/matrix-org/matrix-js-sdk/releases/tag/v12.4.1
- https://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing