Breaking: CVE-2026-22694 - AliasVault is Missing Origin Validation in Android Passkey Credential Provider

Breaking: CVE-2026-22694 - AliasVault is Missing Origin Validation in Android Passkey Credential Provider

CVE ID : CVE-2026-22694 Published : Jan. 14, 2026, 5:16 p.m. | 26 minutes ago Description : AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for a site it was not authorized to access. The issue involved incomplete validation of calling app identity, origin, and RP ID in the Android credential provider. This issue was fixed in AliasVault Android 0.25.3. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 14, 2026
Attack Vector: local

Source: Telegram CVE Monitor