Releases: 44114/gpgapp
Release list
v1.0.1
GPG Key Manager 1.0.1
This release fixes the OpenPGP interoperability and integrity defects reported during the F-Droid review. Key generation, storage and the offline architecture are unchanged.
1.Decrypt messages addressed to the encryption subkey. Ciphertext addressed to the ECDH (X25519) or RSA encryption subkey was rejected with "No matching encrypted data found" — including the app's own output for the default Ed25519/X25519 key type. Subkeys are now resolved correctly, in both directions.
2.Encrypt to the dedicated encryption subkey. RSA messages were encrypted to the primary certify/sign key instead of the E subkey, which other implementations flag as "not marked for encryption use". The encryption-capable subkey is now selected the way GnuPG does it; the primary key is used only if the ring has no usable subkey.
3.Enforce the OpenPGP integrity check (MDC). Decryption ignored the integrity-protection packet, so modified ciphertext decrypted successfully. The packet is now verified before any plaintext is shown, and messages carrying no integrity protection are refused.
4.Fix encrypted packet framing. The encrypted packet declared a fixed size of at least 4096 bytes regardless of the message, producing malformed output ("decryption failed: Invalid packet"). The correct streaming packet form is now used.
5.Add Sign and Verify screens. PGPManager.sign() / verify() were implemented but had no reachable UI, while the store description advertised signing. Both features are now available from the home screen, with strings added in all 19 languages.
6.Update Bouncy Castle to 1.86. Addresses CVE-2026-3505 / GHSA-cj8j-37rh-8475 (unbounded OpenPGP AEAD chunk size), fixed upstream in 1.84. Practical reachability here was limited to locally supplied crafted input, since the app has no network access.
7.Block screenshots of sensitive content. FLAG_SECURE is now set, so key material, passphrases and decrypted text no longer appear in screenshots, screen recordings or the recent-apps thumbnail.
8.Additional hardening. Exported keys and ciphertext no longer share a single result field (exporting a key could overwrite a ciphertext on screen); importing a private key now also stores its public half so it can be used as an encryption recipient.
Please verify the SHA-256 checksum after downloading the file to ensure integrity.
SHA-256 for app-release.apk: 0372b91cddb1555cc379c152f30174dc6f201fda42cb8410985e2ee496ab7fd6