Swift Predictable Iv Nonce Source
Description
This vulnerability detector identifies predictable initialization vectors (IVs) or nonces in Swift CryptoKit encryption operations. Using predictable or static IVs/nonces in cryptographic operations severely weakens encryption security, as it can enable attackers to perform various cryptographic attacks including chosen-plaintext attacks and can reveal patterns in encrypted data.
Detection Strategy
• The code imports the CryptoKit library for cryptographic operations
• A method call is made to a cryptographic sealing/encryption function (such as AES.GCM.seal, ChaCha20Poly1305.seal, or similar)
• The IV or nonce parameter passed to the encryption function uses a predictable source (such as hardcoded values, sequential numbers, or other non-random sources)
• The detector flags the specific encryption call where the predictable IV/nonce is used
Vulnerable code example
import CryptoKit
import Foundation
func encryptWithPredictableNonce(message: Data, key: SymmetricKey) throws -> AES.GCM.SealedBox {
// VULNERABLE: nonce derived from timestamp is predictable to attackers
let nonce = try! AES.GCM.Nonce(data: Data(String(Date().timeIntervalSince1970).utf8))
return try AES.GCM.seal(message, using: key, nonce: nonce)...✅ Secure code example
import CryptoKit
import Foundation
func encryptWithPredictableNonce(message: Data, key: SymmetricKey) throws -> AES.GCM.SealedBox {
// SAFE: no explicit nonce parameter - CryptoKit generates secure random nonce
return try AES.GCM.seal(message, using: key)
}Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.