CVE-2026-100551: OpenClaw iOS Control UI TLS Pin Enforcement Bypass
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by iOS system trust can serve a replacement Control UI page; opening the Terminal or a session Dashboard then allows that page to read the injected Gateway token or password. The stolen credential can grant operator access, including reading sensitive Gateway state and invoking host-capable tools. This issue is fixed in 2026.8.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClaw for iOSto a version that resolves this vulnerability.Fixed in 2026.8.11
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of OpenClaw for iOS versions 2026.7.1 through before 2026.8.11 are exposed if they use the authenticated Terminal or session Dashboard WebViews after accepting a Gateway fingerprint. Native connections continue to enforce the saved Gateway fingerprint.
What does an attacker need to exploit it?
An attacker must be able to redirect the same Gateway host and port to their own server and present a different certificate that iOS system trust accepts. The user must then open the Terminal or a session Dashboard, allowing the replacement Control UI page to access the injected Gateway token or password.
What could an attacker obtain or do with the stolen credential?
The replacement page can read the injected Gateway token or password. Those credentials can provide operator access, including access to sensitive Gateway state and the ability to invoke host-capable tools.
What is the remediation?
Update OpenClaw for iOS to version 2026.8.11, which fixes the missing TLS pin enforcement in the affected Control UI WebViews.