PT-2026-99217 · Openclaw · Openclaw
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw for iOS versions prior to 2026.8.11
Description
The application stores Gateway credentials as cleartext JSON within App Group UserDefaults rather than using the secure device Keychain. This allows attackers who obtain unencrypted device backups or extracted App Group containers to recover valid Gateway tokens and passwords, enabling them to authenticate with operator authority.
Recommendations
Update OpenClaw for iOS to version 2026.8.11 or later.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw