Sender-binding gaps in to-device messages
| Details |
|
| Package |
matrix-sdk-crypto |
| Version |
0.16.0 |
| URL |
GHSA-wfq4-36m3-9g42 |
| Date |
2026-06-03 |
| Patched versions |
>=0.16.1 |
| Unaffected versions |
<0.12.0 |
The matrix-sdk-crypto crate before 0.16.1 is missing a check for the sender's
user ID when decrypting an Olm-encrypted to-device message containing the
sender_device_keys property.
This could be exploited to spoof the sender of an encrypted to-device message,
but only if the attacker colludes with (or is) the homeserver operator.
See advisory page for additional details.
matrix-sdk-crypto0.16.0>=0.16.1<0.12.0The matrix-sdk-crypto crate before 0.16.1 is missing a check for the sender's
user ID when decrypting an Olm-encrypted to-device message containing the
sender_device_keys property.
This could be exploited to spoof the sender of an encrypted to-device message,
but only if the attacker colludes with (or is) the homeserver operator.
See advisory page for additional details.