Out-of-bounds write in keepassxc - #VU151869
Published: September 23, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in BrowserMessageBuilder browser-integration response encryption when encrypting oversized authorized browser-integration responses. A local user can send a crafted get-logins request to cause a denial of service.
Exploitation requires access to the per-user browser IPC endpoint, a valid database association key, and an unlocked database.