External risk intelligence

OpenClaw for iOS Control UI TLS Pin Enforcement Bypass Leading to Credential Theft.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-100551

The vulnerability affects an iOS application's local WebViews. While it involves network communication with a Gateway, the attack requires the user to be directed to a malicious host and successfully interact with the compromised UI, making direct public internet exposure of the vulnerable interface uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in a specific iOS application where saved security credentials for the Gateway connection were not properly enforced in certain user interfaces. This could allow an attacker, under specific circumstances, to intercept sensitive access tokens or passwords, potentially granting them operator access to the system.

  • Security checks for gateway connections failed.
  • Stolen credentials could grant unauthorized access.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could redirect a user to a malicious version of a trusted host and port, presenting a fake web page through the application's Control UI. This fake page can then steal credentials when the user accesses the Terminal or Dashboard, allowing the attacker to gain operator access and control sensitive gateway functions.

  • Requires user interaction to visit a malicious site.
  • Triggered by opening Terminal or Dashboard WebViews.
  • Risk of stolen credentials and unauthorized access.

Live Threat

Current exploitation, exposure, and threat context

The Control UI in OpenClaw for iOS, when supported by the advisory, could expose sensitive Gateway information if a user accepts a Gateway fingerprint and an attacker can redirect network traffic. This redirection allows the attacker to present a malicious Control UI page that can steal the Gateway token or password. The stolen credentials could grant an attacker operator access, enabling them to view sensitive Gateway states and execute host-capable tools.

  • Gateway tokens and passwords.
  • User accepts a redirected malicious host.
  • Operator access and sensitive data theft.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability primarily impacts the OpenClaw application on iOS, specifically within its Control UI's handling of TLS pins. The first practical move is for the application owner or mobile platform team to identify all iOS devices running the affected versions, assess whether these devices can connect to a compromised network, and then confirm the business criticality of the OpenClaw application before planning remediation.

  • Application owners should prioritize this.
  • Verify affected iOS devices and network reachability.
  • Plan coordinated updates with users.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OpenClaw for iOS?

OpenClaw for iOS is a mobile application used to manage and interact with remote Gateways. It provides a Control UI that includes a Terminal and session Dashboard, allowing users to monitor system states and execute administrative tools on connected hosts.

What is the vulnerability in CVE-2026-100551?

This vulnerability involves a failure to enforce TLS pinning, categorized as CWE-295 (Improper Certificate Validation). While the app correctly pins certificates for native connections, its web-based components—the Terminal and Dashboard—fail to verify these saved security fingerprints, allowing a malicious server to impersonate a legitimate Gateway.

How can an attacker trigger this issue?

An attacker must successfully redirect the user to a malicious host and port that presents an alternative certificate trusted by the iOS system. The bug is specifically triggered when the user interacts with the app by opening the Terminal or session Dashboard WebViews while connected to this malicious environment.

Do I need to worry about this if I use OpenClaw internally?

Halo Surface Signal notes that this vulnerability is unlikely to be triggered over the public internet, as it requires specific user interaction with a compromised host. However, you should still evaluate your risk based on whether users might connect to untrusted or intercepting networks where such redirection could occur.

When should I update my OpenClaw application?

You should plan to update to version 2026.8.11 as soon as possible. Start by identifying all iOS devices running the vulnerable versions in your environment, assess their potential for connecting to untrusted networks, and coordinate a rollout of the update to those users to ensure proper certificate enforcement.

References