---
id: CVE-2026-100581
title: >-
  OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON
  in App Group UserDefaults instead of the device Keychain
summary: >-
  OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON
  in App Group UserDefaults instead of the device Keychain. Attackers with
  access to unencrypted device backups or extracted App Group containers can
  recover va…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-312
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.8.11
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T03:17:05.930'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100581'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-gcm4-fmcp-2f9r
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-ios-before-2026.8.11-credential-storage-via-share-extension
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T03:25:24.692Z'
---

## Overview

OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the device Keychain. Attackers with access to unencrypted device backups or extracted App Group containers can recover valid Gateway tokens and passwords to authenticate with operator authority.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
