Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

electerm's encrypt method not safe enough

GHSA-g29v-q6h7-76wh · CVE-2026-45787

Published · Modified

Description

Impact

Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to alter config/bookmarks.

Patches

Workarounds

  • No

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes