Kotlin Predictable Iv Nonce Source
Description
This vulnerability detector identifies insecure cryptographic cipher initialization in Kotlin code where predictable initialization vectors (IV) or nonces are used with encryption modes. Using predictable or static IVs/nonces severely weakens cryptographic security by making encrypted data vulnerable to pattern analysis and cryptographic attacks.
Detection Strategy
• Report vulnerability when a cipher initialization method call is found in Kotlin code
• The method call must be an initialization method (ending with specific init pattern)
• The method must have both a mode argument and a specification argument in the expected positions
• The mode argument must specify an encryption mode that requires secure IVs/nonces
• The specification argument must contain a predictable or insecure IV/nonce construction pattern
• Both conditions (unsafe encryption mode AND predictable IV construction) must be present simultaneously
Vulnerable code example
import java.nio.ByteBuffer
import javax.crypto.Cipher
import javax.crypto.spec.SecretKeySpec
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.GCMParameterSpec
fun encryptData(data: ByteArray, key: SecretKeySpec): ByteArray {
val cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")...✅ Secure code example
import java.nio.ByteBuffer
import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.SecretKeySpec
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.GCMParameterSpec
fun encryptData(data: ByteArray, key: SecretKeySpec): ByteArray {...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.