Impact
The flaw lies in the MLS (RFC 9420) implementation in Bouncy Castle for Java, where an X.509 credential is not bound to the LeafNode’s signature key. LeafNode.verify() checked the signature against the key stored in the leaf itself, but the certificate chain was never parsed or validated. As a consequence, an attacker could present a different party’s certificate while signing a leaf and be accepted under that other party’s identity. The attacker would then obtain membership, evict a victim, derive the current epoch, decrypt future messages, and impersonate the victim in group communications.
Affected Systems
Legion of the Bouncy Castle Inc.’s BC-JAVA libraries before version 1.86 are affected. Systems that deploy MLS and rely on Bouncy Castle for cryptographic operations may be vulnerable if they do not perform independent credential admission checks.
Risk and Exploitability
The vulnerability scores a CVSS of 9.2, indicating critical severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is the network, where an adversary crafts malicious MLS KeyPackage messages that exploit the missing certificate-key binding check. Successful exploitation allows an unauthenticated attacker to be admitted under a valid X.509 identity, enabling full impersonation and confidentiality compromise of subsequent group traffic.
OpenCVE Enrichment