Kotlin Short Gcm Auth Tag
Description
This detector identifies Kotlin code that encrypts data with AES-GCM using an authentication tag shorter than 96 bits. A truncated tag lowers the cost of forging ciphertexts, so an attacker can tamper with encrypted data and have it accepted as authentic, compromising its integrity.
Detection Strategy
• The code must import the javax.crypto.spec package
• The detector examines Cipher init calls made in encrypt mode and resolves the parameter specification argument
• It checks that the specification is a GCMParameterSpec and examines its first argument, the tag length in bits
• A vulnerability is reported when the tag length is a literal, or a variable that resolves to one, below 96 bits
• Tag lengths received as function parameters, and specifications used in decrypt mode, are not reported
Vulnerable code example
import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.GCMParameterSpec
import javax.crypto.spec.SecretKeySpec
fun encrypt(keySpec: SecretKeySpec, data: ByteArray): ByteArray {
val iv = ByteArray(12)
SecureRandom.getInstanceStrong().nextBytes(iv)...✅ Secure code example
import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.GCMParameterSpec
import javax.crypto.spec.SecretKeySpec
fun encrypt(keySpec: SecretKeySpec, data: ByteArray): ByteArray {
val iv = ByteArray(12)
SecureRandom.getInstanceStrong().nextBytes(iv)...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, fill out this contact form.