logo

Database

Kotlin Predictable Iv Nonce Source

Description

This vulnerability detector identifies insecure cryptographic cipher initialization in Kotlin code where predictable initialization vectors (IV) or nonces are used with encryption modes. Using predictable or static IVs/nonces severely weakens cryptographic security by making encrypted data vulnerable to pattern analysis and cryptographic attacks.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Report vulnerability when a cipher initialization method call is found in Kotlin code

    • The method call must be an initialization method (ending with specific init pattern)

    • The method must have both a mode argument and a specification argument in the expected positions

    • The mode argument must specify an encryption mode that requires secure IVs/nonces

    • The specification argument must contain a predictable or insecure IV/nonce construction pattern

    • Both conditions (unsafe encryption mode AND predictable IV construction) must be present simultaneously

Vulnerable code example

import java.nio.ByteBuffer
import javax.crypto.Cipher
import javax.crypto.spec.SecretKeySpec
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.GCMParameterSpec

fun encryptData(data: ByteArray, key: SecretKeySpec): ByteArray {
    val cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")...

✅ Secure code example

import java.nio.ByteBuffer
import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.SecretKeySpec
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.GCMParameterSpec

fun encryptData(data: ByteArray, key: SecretKeySpec): ByteArray {...