I haven't traced through the app's code to verify that is true.
Recommendation: If there is no HMAC tag with a ciphertext, immediately throw an exception. It makes it clearer that a decryption failure occurred (thus avoiding false positives).
Recommendation: If there is no HMAC tag with a ciphertext, immediately throw an exception. It makes it clearer that a decryption failure occurred (thus avoiding false positives).
[1]: https://github.com/bitwarden/jslib/blob/master/src/services/...
The AES-CBC thing is tied to the key, right? So the downgrade attack isn't possible.