HackerFeeds
All CVEs

CVE-2026-103097

HIGH7.5

Published 2026-10-02 · Source 0df08a0e-a200-4957-9bb0-084f562506f9

Description

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CWE-312CWE-540CWE-798
View on NVD