logo

Database

Swift Predictable Iv Nonce Source

Description

This vulnerability detector identifies predictable initialization vectors (IVs) or nonces in Swift CryptoKit encryption operations. Using predictable or static IVs/nonces in cryptographic operations severely weakens encryption security, as it can enable attackers to perform various cryptographic attacks including chosen-plaintext attacks and can reveal patterns in encrypted data.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • The code imports the CryptoKit library for cryptographic operations

    • A method call is made to a cryptographic sealing/encryption function (such as AES.GCM.seal, ChaCha20Poly1305.seal, or similar)

    • The IV or nonce parameter passed to the encryption function uses a predictable source (such as hardcoded values, sequential numbers, or other non-random sources)

    • The detector flags the specific encryption call where the predictable IV/nonce is used

Vulnerable code example

import CryptoKit
import Foundation

func encryptWithPredictableNonce(message: Data, key: SymmetricKey) throws -> AES.GCM.SealedBox {
    // VULNERABLE: nonce derived from timestamp is predictable to attackers
    let nonce = try! AES.GCM.Nonce(data: Data(String(Date().timeIntervalSince1970).utf8))
    
    return try AES.GCM.seal(message, using: key, nonce: nonce)...

✅ Secure code example

import CryptoKit
import Foundation

func encryptWithPredictableNonce(message: Data, key: SymmetricKey) throws -> AES.GCM.SealedBox {
    // SAFE: no explicit nonce parameter - CryptoKit generates secure random nonce
    return try AES.GCM.seal(message, using: key)
}