Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. matrix-ios-sdk version 0.23.19 has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This attack requires coordination between a malicious home server and an attacker, so those who trust their home servers do not need a workaround. To avoid malicious backup attacks, one should not verify one's new logins using emoji/QR verifications methods until patched.
{
"cwe_ids": [
"CWE-287",
"CWE-322"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39255.json"
}{
"cpe": "cpe:2.3:a:matrix:software_development_kit:*:*:*:*:*:iphone_os:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.23.19"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-22T02:08:01Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"72316361310660215691931429924248656841",
"189705816796646848369622463688827033150",
"2759542088427777407975446035108501989",
"288326346438592934844332775474134550390"
]
},
"signature_version": "v1",
"source": "https://github.com/matrix-org/matrix-ios-sdk/commit/5ca86c328a5faaab429c240551cb9ca8f0f6262c",
"id": "CVE-2022-39255-07dcc288",
"target": {
"file": "MatrixSDK/MatrixSDK.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"67533782217048731478845813822640661200",
"179363983628606553136196328013506286956",
"85506329710230119266986245676459050459",
"269738058025597410218216131962536513506"
]
},
"signature_version": "v1",
"source": "https://github.com/matrix-org/matrix-ios-sdk/commit/5ca86c328a5faaab429c240551cb9ca8f0f6262c",
"id": "CVE-2022-39255-6b1b9555",
"target": {
"file": "MatrixSDK/Crypto/KeyBackup/Data/MXKeyBackupVersionTrust.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"66351378363967913525731711829179713061",
"278095958396896172607945763059320629255",
"28855884788969288805322590027579852764",
"170155866619890102279608280462406778425",
"239071177152843437385360301179989644514"
]
},
"signature_version": "v1",
"source": "https://github.com/matrix-org/matrix-ios-sdk/commit/5ca86c328a5faaab429c240551cb9ca8f0f6262c",
"id": "CVE-2022-39255-9ce392d5",
"target": {
"file": "MatrixSDK/Crypto/MXCrypto_Private.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"272668942739153391175570236843389917764",
"219901029857565321632056379059209492978",
"302059645746209613230955050501983567248",
"1672072197779040601041217422215633176",
"335840380194476245255822729622053932410",
"52316583242005744414175263803774447983",
"175349735087660708318188361192521530113",
"156142438452545808743477145715136721228"
]
},
"signature_version": "v1",
"source": "https://github.com/matrix-org/matrix-ios-sdk/commit/5ca86c328a5faaab429c240551cb9ca8f0f6262c",
"id": "CVE-2022-39255-a38faaa9",
"target": {
"file": "MatrixSDK/Crypto/Algorithms/MXDecrypting.h"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"95370822025649101032070280231532536163",
"218538451127144728946738354929452478915",
"8240106280630917728025718766878528805",
"120226752188299944594824832498015762984"
]
},
"signature_version": "v1",
"source": "https://github.com/matrix-org/matrix-ios-sdk/commit/5ca86c328a5faaab429c240551cb9ca8f0f6262c",
"id": "CVE-2022-39255-a972c3de",
"target": {
"file": "MatrixSDK/Crypto/MXOlmDevice.h"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39255.json"