CVE-2022-45195
MEDIUMSimpleXMQ < 3.4.0 and SimpleX Chat < 4.2 - Use of a Broken Cryptographic Algorithm in X3DH Key Exchange
Title source: llmDescription
SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, which can interfere with forward secrecy and can have other impacts if there is a compromise of a single private key. This occurs in the X3DH key exchange for the double ratchet protocol.
References (4)
Core 4
Core References
Release Notes, Third Party Advisory
https://github.com/simplex-chat/simplexmq/compare/v3.3.0...v3.4.0
Patch, Third Party Advisory
https://github.com/simplex-chat/simplexmq/pull/548
Exploit, Technical Description, Third Party Advisory
https://github.com/trailofbits/publications/blob/master/reviews/SimpleXChat.pdf
Release Notes, Vendor Advisory
https://simplex.chat/blog/20221108-simplex-chat-v4.2-security-audit-new-website.html
Scores
CVSS v3
5.3
EPSS
0.0058
EPSS Percentile
43.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-327
Status
published
Products (2)
simplex/simplex_chat
< 4.2
simplex/simplexmq
< 3.4.0
Published
Nov 12, 2022
Tracked Since
Feb 18, 2026