Executive brief
Matrix's JavaScript SDK for end-to-end encrypted messaging accepts improperly encrypted messages, allowing an attacker colluding with a malicious homeserver to forge messages appearing to come from other users. An attacker could inject fake key backup secrets or other sensitive data, potentially compromising message authenticity and user verification systems without visible warnings to the recipient.
Technical details
The vulnerability stems from a protocol confusion flaw in the Olm/Megolm encryption handling: the SDK incorrectly accepts to-device messages encrypted with Megolm instead of requiring the stricter Olm encryption. This allows an attacker coordinating with a malicious homeserver to construct forged messages with a legitimate origin appearance. The attack vector is network-based and requires no user interaction or special authentication. An attacker can spoof message sources, inject backdoored key backup secrets during self-verification flows, or manipulate device keys. The fix restricts to-device messages to Olm encryption only, adds validation for key backup signatures from trusted devices, and discards cleartext cryptographic material messages. Version 19.7.0 and later contain the patches.
Affected products
- Matrix matrix-js-sdk <19.7.0
Timeline
- 2022-09-28: disclosed: Security advisory published
- 2022-09-30: patched: Version 19.7.0 released with fixes