CVE-2026-100581: OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension
OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to credential recovery?
OpenClaw for iOS installations before 2026.8.11 are exposed if an attacker can obtain an unencrypted device backup or extract the application's App Group container.
What does an attacker need to exploit this issue?
The attacker needs local access sufficient to access an unencrypted backup or extracted App Group container. No user interaction is required, but the attack requires low-level local access and low privileges.
What can recovered credentials be used for?
Recovered Gateway tokens and passwords can be used to authenticate with operator authority. The reported impact is high confidentiality impact, with no reported integrity or availability impact.
How can I determine whether credentials may be exposed?
Systems running OpenClaw for iOS before 2026.8.11 should be treated as potentially affected, particularly where unencrypted device backups or App Group container extraction may have occurred. The affected storage location is cleartext JSON in App Group UserDefaults rather than the device Keychain.