HomeSecurityMatrix: Vulnerabilities found in end-to-end encryption

Matrix: Vulnerabilities found in end-to-end encryption

Decentralized communication platform Matrix has published a security advisory regarding two critical vulnerabilities affecting end-to-end encryption in its software development kit (SDK).

A threat actor exploiting these flaws could breach the confidentiality of Matrix and perform “man-in-the-middle” that expose message contents in readable form.

Customers affected by the bugs are those using matrix-js-sdk, matrix-ios-sdk , and matrix-android-sdk2, such as Element, Beeper, Cinny, SchildiChat, Circuli and Synod.im.

Other clients using a different encryption application (e.g. Hydrogen, ElementX, Nheko, FluffyChat, Syphon, Timmy, Gomuks, Pantalaimon) are not affected.

Matrix emphasizes that the issues have been fixed and all users need to do to keep their communications secure is to apply the available updates to their IM clients.

Matrix 's statement claims that exploiting the flaws is not an easy task and that they have not seen evidence of active exploitation.

Matrix: Vulnerabilities found in end-to-end encryption
Matrix: Vulnerabilities found in end-to-end encryption

The security issues lie in the implementation of the encryption mechanisms, not the protocol itself. The vulnerabilities were discovered by researchers at Brave Software, Royal Holloway University in London, and the University of Sheffield , and were responsibly disclosed to Matrix.

The team has also published a technical paper detailing its findings and presenting six examples of attacks that exploit the vulnerabilities.

See also: Witchetty group: Hides backdoor malware inside Windows logo

In summary, the critical vulnerabilities discovered by the team are the following:

CVE-2022-39250: Key/Device identifier confusion bug in SAS verification in matrix-js-sdk , allowing a malicious server administrator to circumvent emoji-based verification when cross-signing is used, authenticating themselves instead of the target user.

CVE-2022-39251: Protocol confusion bug in matrix-js-sdk, leading to incorrect acceptance of messages from a spoofed sender, opening the possibility of impersonating a trusted sender. The same flaw allows malicious homeserver admins to add backup keys to the target account.

CVE-2022-39255: Same as CVE-2022-39251 but affects matrix-ios-sdk (iOS clients).

CVE-2022-39248: Same as CVE-2022-39251 but affects matrix-android-sdk2 (Android clients).

In addition to the issues above, the following lower severity problems were also identified:

CVE-2022-39249: Semi-trusted impersonation issue in matrix-js-sdk that leads to acceptance of unsolicited keys, allowing impersonation of other users on the server. Clients flag these messages as suspicious on the recipient side, so the severity of the bug is reduced.

CVE-2022-39257: Same as CVE-2022-39249 but affects matrix-ios-sdk (iOS clients).

CVE-2022-39246: Same as CVE-2022-39249 but affects matrix-android-sdk2 (Android clients).

Matrix: Vulnerabilities found in end-to-end encryption
Matrix: Vulnerabilities found in end-to-end encryption

There are also two vulnerabilities that have not yet received an identification number. One of them is an issue that allows a malicious homeserver to forge invites on behalf of its users or add devices to user accounts.

The second refers to the use of AES-CTR to encrypt attachments, secrets, and symmetric key backups without an AES initialization vector, which makes it insecure.

One thing the researchers who discovered the flaws point out is that the cryptographic building blocks of Matrix are strong, yet the project seems to have a loose way of putting everything together securely.

See also: Microsoft Exchange zero-day actively used in attacks

The variety of bug types (insecure by design, protocol confusion, lack of domain separation, implementation bugs) and the fact that the impact is spread across multiple subprotocols and libraries seems to confirm what is emphasized in the white paper:

"In addition to the observed implementation and specification errors, these vulnerabilities highlight the lack of a unified and formal approach to Matrix.
Rather, the specifications and implementations appear to have evolved 'organically' with new subprotocols adding new functionality and thus inadvertently subverting the security assurances of the core protocol.
This suggests that, in addition to fixing the specific vulnerabilities reported here, Matrix/Megolm will need to receive a formal security analysis to establish confidence in its design."

Matrix is ​​currently focused on developing cleaner and more secure 2nd and 3rd generation SDKs written in Rust , and it's worth noting that the flaws discovered do not affect these newer generation SDKs.

Thunderbird , which added support for Matrix VOIP and chat in version 102 released in June 2022, has also pushed out a security update yesterday that addresses the issues.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS