Critical vulnerabilities compromising end-to-end encryption in many Matrix clients.

The developers of the decentralized communication platform Matrix have warned of critical vulnerabilities discovered in the libraries matrix-js-sdk, matrix-ios-sdk, and matrix-android-sdk2, which allow server administrators to impersonate other users and read messages in end-to-end encrypted (E2EE) chats. These vulnerabilities are caused by errors in specific implementations of the Matrix protocol and are not issues with the protocol itself. Updates for the problematic SDKs and some client applications built on them have been released by the project.

To successfully carry out an attack, an attacker must access a controlled home server server (homeserver - the server for storing client history and accounts). The application of end-to-end encryption on the client side does not allow the administrator to server intercept message exchanges, but the identified vulnerabilities enable bypassing this protection. The issues affect the primary Matrix client Element (formerly Riot) for Web, desktop systems, iOS, and Android, as well as third-party client applications including Cinny, Beeper, SchildiChat, Circuli, and Synod.im. Vulnerabilities do not manifest in the libraries matrix-rust-sdk, hydrogen-sdk, Matrix Dart SDK, mautrix-python, mautrix-go, and matrix-nio, or in the applications Hydrogen, ElementX, Nheko, FluffyChat, Syphon, Timmy, Gomuks, and Pantalaimon.

Three main attack scenarios are outlined:

  • A Matrix server administrator can disrupt the emoji-based verification (SAS, Short Authentication Strings) when using cross-signatures and impersonate another user. This issue is caused by a vulnerability (CVE-2022-39250) in the matrix-js-sdk code, related to the mixing of handling device identifiers and cross-signing keys.
  • A controlling server operator can forge a trusted sender and pass a fake key to intercept messages from other users. This issue stems from vulnerabilities in matrix-js-sdk (CVE-2022-39251), matrix-ios-sdk (CVE-2022-39255), and matrix-android-sdk2 (CVE-2022-39248), which caused the client to incorrectly accept device-addressed messages encrypted using the Megolm protocol instead of Olm, attributing the messages to the Megolm sender rather than the actual sender.
  • By exploiting the vulnerabilities mentioned in the previous point, the server administrator can also add a dummy backup key to a user account to retrieve the keys used for message encryption.

Researchers who identified the vulnerability also demonstrated attacks leading to the addition of unauthorized users to the chat or the attachment of foreign devices to a user. These attacks are based on the fact that service messages used to add users to a chat are not tied to the chat creator's keys and can be generated by the server administrator. Developers from the Matrix project categorized these vulnerabilities as minor, as such manipulations would not go unnoticed — in the case of user substitution, the individual will appear in the chat user list, and when adding a device, a warning will be displayed, marking the device as unverified (immediately after adding a substituted device, shared keys necessary for decrypting messages will begin to be transmitted).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster