MEDIUM 6.8 NVD
CVE-2026-100581
OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access t
OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority.
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-gcm4-fmcp-2f9r
- https://www.vulncheck.com/advisories/openclaw-ios-before-2026.8.11-credential-storage-via-
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11591 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.