CVE-2026-22694
📋 TL;DR
This vulnerability in AliasVault Android app allows a malicious local app to potentially obtain passkey responses for websites it shouldn't have access to. The issue stems from incomplete validation of app identity, origin, and RP ID in the credential provider. Only Android users running AliasVault versions 0.24.0 through 0.25.2 are affected.
💻 Affected Systems
- AliasVault Android
📦 What is this software?
Aliasvault by Aliasvault
⚠️ Risk & Real-World Impact
Worst Case
A malicious app could steal passkey credentials for sensitive websites, potentially leading to account compromise and identity theft.
Likely Case
Local malicious app could access passkeys for some websites, but requires specific conditions and user interaction patterns.
If Mitigated
With proper app isolation and user awareness, impact is limited to potential exposure of non-critical passkeys.
🎯 Exploit Status
Requires local malicious app installation and specific conditions. No public exploit code available.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: 0.25.3
Vendor Advisory: https://github.com/aliasvault/aliasvault/security/advisories/GHSA-mvg4-wvjv-332q
Restart Required: Yes
Instructions:
1. Open Google Play Store 2. Search for AliasVault 3. Tap Update to version 0.25.3 or higher 4. Restart the app after update
🔧 Temporary Workarounds
Disable passkey functionality
androidTemporarily disable passkey features in AliasVault settings until patched
Uninstall suspicious apps
androidRemove any unknown or untrusted apps from Android device
🧯 If You Can't Patch
- Uninstall AliasVault and use alternative password manager
- Enable Android Play Protect and only install apps from trusted sources
🔍 How to Verify
Check if Vulnerable:
Check AliasVault version in app settings: Settings > About > Version
Check Version:
Not applicable - check via app UI
Verify Fix Applied:
Confirm version is 0.25.3 or higher in app settings
📡 Detection & Monitoring
Log Indicators:
- Unusual passkey request patterns
- Multiple failed credential validations
Network Indicators:
- Not applicable - local vulnerability
SIEM Query:
Not applicable for local Android app vulnerability
🔗 References
- https://github.com/aliasvault/aliasvault/commit/b3350473103d6138ab2b63ca130c211717eac67d
- https://github.com/aliasvault/aliasvault/issues/1440
- https://github.com/aliasvault/aliasvault/pull/1441
- https://github.com/aliasvault/aliasvault/releases/tag/0.25.3
- https://github.com/aliasvault/aliasvault/security/advisories/GHSA-mvg4-wvjv-332q