> CVE-2021-23827: Sakura Samurai discover cleartext pictures in Keybase Desktop Client; Windows, macOS, Linux
[DATE: 22/02/2021 04:00]
[LANGUAGE: EN]
Credits John
Github: https://github.com/johnjhacking
Aubrey Cottle
Twitter: https://twitter.com/Kirtaner
Jackson Henry
Twitter: https://twitter.com/JacksonHHax
Robert Willis
Twitter: https://twitter.com/rej_ex
Identification During security research, John Jackson stumbled upon the Keybase Client directories and decided to take a look considering Keybase operates a Bug Bounty Program. Within several minutes, John noticed a directory named “uploadtemps”
C:\Users\yourusername\AppData\Local\Keybase\uploadtemps
The directory contained randomized folders:
John noticed that inside of these folders, photos that had been previously pasted into conversations [but deleted through either normal means or exploded] remained, unencrypted.