An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for ChatSecure (3.2.0 - 4.0.0; only iOS) and Zom (all versions up to 1.0.11; only iOS).
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:zom:zom:*:*:*:*:*:iphone_os:*:*"
],
"extracted_events": [
{
"last_affected": "1.0.11"
}
],
"vendor_product": "zom:zom",
"source": "CPE_RANGE"
},
{
"cpes": [
"cpe:2.3:a:chatsecure:chatsecure:3.2.0:*:*:*:*:iphone_os:*:*",
"cpe:2.3:a:chatsecure:chatsecure:4.0.0:*:*:*:*:iphone_os:*:*"
],
"extracted_events": [
{
"introduced": "3.2.0"
},
{
"last_affected": "3.2.0"
},
{
"introduced": "4.0.0"
},
{
"last_affected": "4.0.0"
}
],
"vendor_product": "chatsecure:chatsecure",
"source": "CPE_STRING"
}
]
}{
"cpe": [
"cpe:2.3:a:chatsecure:chatsecure:3.2.1:*:*:*:*:iphone_os:*:*",
"cpe:2.3:a:chatsecure:chatsecure:3.2.2:*:*:*:*:iphone_os:*:*",
"cpe:2.3:a:chatsecure:chatsecure:3.2.3:*:*:*:*:iphone_os:*:*"
],
"extracted_events": [
{
"introduced": "3.2.1"
},
{
"last_affected": "3.2.1"
},
{
"introduced": "3.2.2"
},
{
"last_affected": "3.2.2"
},
{
"introduced": "3.2.3"
},
{
"last_affected": "3.2.3"
}
],
"source": [
"CPE_STRING",
"REFERENCES"
]
}"2026-07-08T16:53:17Z"
[
{
"target": {
"file": "ChatSecure/Classes/Controllers/XMPP/OTRXMPPMessageYapStroage.h"
},
"id": "CVE-2017-5590-938e6ade",
"digest": {
"line_hashes": [
"209646930666600076338162883704913539223",
"273743801690347581989655561691106847040",
"180914673249055266491887896319264413105",
"131330495340382908432222828795181426082"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/chatsecure/chatsecure-ios/commit/a340b4bb519227d89f85f2716a10a197a65d4856"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5590.json"