CVE-2021-34421
Status: ModifiedMedium (4.3)—
The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.71%
- Percentile among all scored CVEs: 52
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-459
References
Raw JSON (NVD)
Show
{
"id": "CVE-2021-34421",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@zoom.us",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@zoom.us",
"affectedData": [
{
"vendor": "Zoom Video Communications Inc",
"product": "Keybase Client for Android",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.8.0",
"versionType": "custom"
}
]
},
{
"vendor": "Zoom Video Communications Inc",
"product": "Keybase Client for iOS",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "5.8.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-11-11T23:15:09.997",
"references": [
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin",
"tags": [
"Third Party Advisory"
],
"source": "security@zoom.us"
},
{
"url": "https://explore.zoom.us/en/trust/security/security-bulletin",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-459"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from the customer's device."
},
{
"lang": "es",
"value": "Keybase Client para Android versiones anteriores a 5.8.0 y Keybase Client para iOS versiones anteriores a 5.8.0 no eliminan correctamente los mensajes explotados iniciados por un usuario si el usuario receptor coloca la sesión de chat en segundo plano mientras el usuario emisor explota los mensajes. Esto podría conllevar a una divulgación de información confidencial que debía ser eliminada del dispositivo del cliente"
}
],
"lastModified": "2026-06-17T03:55:49.467",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:keybase:keybase:5.8.0:*:*:*:*:android:*:*",
"vulnerable": true,
"matchCriteriaId": "B10E64A0-3C0E-4ED3-9978-2DE883191A06"
},
{
"criteria": "cpe:2.3:a:keybase:keybase:5.8.0:*:*:*:*:iphone_os:*:*",
"vulnerable": true,
"matchCriteriaId": "FC887BBA-4A93-49C7-83F0-F7A5BCD65BA1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@zoom.us"
}