Description

AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for a site it was not authorized to access. The issue involved incomplete validation of calling app identity, origin, and RP ID in the Android credential provider. This issue was fixed in AliasVault Android 0.25.3.

INFO

Published Date :

2026-01-14T16:32:36.007Z

Last Modified :

2026-01-14T16:59:24.012Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-22694 vulnerability.

Vendors Products
Aliasvault
  • Aliasvault
Google
  • Android

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact