PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5589 Yaxim CVE debrief

CVE-2017-5589 is a display-impersonation flaw in yaxim and Bruno for Android. According to the NVD record, an incorrect implementation of XEP-0280: Message Carbons can let a remote attacker make messages appear as if they came from another user, including contacts, which creates a social-engineering risk.

Vendor
Yaxim
Product
Bruno
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-09
Original CVE updated
2026-05-13
Advisory published
2017-02-09
Advisory updated
2026-05-13

Who should care

Organizations or individuals using yaxim or Bruno on Android, especially versions 0.8.6 through 0.8.8, should care because the flaw can mislead users by spoofing the apparent sender of messages.

Technical summary

The vulnerability is described as an incorrect implementation of XEP-0280 (Message Carbons) in multiple XMPP clients. NVD lists yaxim and Bruno on Android 0.8.6, 0.8.7, and 0.8.8 as affected. The impact is integrity-related display spoofing: a remote attacker can impersonate users in the application’s UI, enabling convincing social-engineering attacks. The CVSS vector provided by NVD is CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N.

Defensive priority

Medium. The issue is network-reachable and can affect trust in message identity, but the documented impact is limited to impersonation in the client display rather than direct code execution or data theft.

Recommended defensive actions

  • Upgrade yaxim or Bruno to a version that includes the upstream fix referenced by the project commit.
  • If immediate upgrading is not possible, treat sender identity in affected clients with extra caution and verify sensitive requests through an independent channel.
  • Review deployments for Android devices running yaxim or Bruno 0.8.6 through 0.8.8 and prioritize them for remediation.
  • Use the NVD record and the linked upstream patch reference to confirm the corrected build or release in your environment.

Evidence notes

The NVD CVE record states the issue is an incorrect implementation of XEP-0280: Message Carbons and lists affected CPEs for yaxim and Bruno versions 0.8.6, 0.8.7, and 0.8.8 on Android. The record also references an upstream GitHub patch commit and a third-party technical advisory that discuss the flaw. Published date used here is 2017-02-09, per the supplied CVE timeline.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5589 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5589

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5589 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5589

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.