Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in a specific iOS application where saved security credentials for the Gateway connection were not properly enforced in certain user interfaces. This could allow an attacker, under specific circumstances, to intercept sensitive access tokens or passwords, potentially granting them operator access to the system.
- Security checks for gateway connections failed.
- Stolen credentials could grant unauthorized access.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker could redirect a user to a malicious version of a trusted host and port, presenting a fake web page through the application's Control UI. This fake page can then steal credentials when the user accesses the Terminal or Dashboard, allowing the attacker to gain operator access and control sensitive gateway functions.
- Requires user interaction to visit a malicious site.
- Triggered by opening Terminal or Dashboard WebViews.
- Risk of stolen credentials and unauthorized access.
Live Threat
Current exploitation, exposure, and threat context
The Control UI in OpenClaw for iOS, when supported by the advisory, could expose sensitive Gateway information if a user accepts a Gateway fingerprint and an attacker can redirect network traffic. This redirection allows the attacker to present a malicious Control UI page that can steal the Gateway token or password. The stolen credentials could grant an attacker operator access, enabling them to view sensitive Gateway states and execute host-capable tools.
- Gateway tokens and passwords.
- User accepts a redirected malicious host.
- Operator access and sensitive data theft.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability primarily impacts the OpenClaw application on iOS, specifically within its Control UI's handling of TLS pins. The first practical move is for the application owner or mobile platform team to identify all iOS devices running the affected versions, assess whether these devices can connect to a compromised network, and then confirm the business criticality of the OpenClaw application before planning remediation.
- Application owners should prioritize this.
- Verify affected iOS devices and network reachability.
- Plan coordinated updates with users.