Junglewise Threat Intelligence

CVE-2026-95815: OpenClaw iOS credential logging in diagnostic archives

CVE-2026-95815 · Severity: medium · CVSS 6.3 · Published 2026-09-22

Vendors: Openclaw.

Executive brief

OpenClaw is an AI agent application for iOS that uses deep links to submit agent requests. The app logs complete deep-link URLs containing persistent bearer authentication keys to system diagnostic logs, which are treated as public data. An attacker who obtains a device's diagnostic archive can extract these unrotated keys and replay them to submit forged agent requests without requiring local confirmation from the user.

Technical details

The iOS application logs complete agent deep-link URLs containing persistent bearer keys to unified logs as public diagnostic data, failing to redact sensitive authentication material. An unauthenticated attacker with access to a diagnostic archive can recover these keys and replay them in forged deep links to bypass the local confirmation prompt required for agent request submission. The vulnerability affects iOS versions before 2026.8.11.

Affected products

  • OpenClaw iOS before 2026.8.11

Timeline

  • 2026-09-22: disclosed

References