"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may allow a local attacker to analyze data in the app and to obtain API key for an external service.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: jpcert

Published: 2023-06-30T06:22:37.864Z

Updated: 2023-06-30T06:22:37.864Z

Reserved: 2023-03-15T08:11:31.618Z


Link: CVE-2023-28387

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-06-30T07:15:08.720

Modified: 2023-07-07T18:24:25.427


Link: CVE-2023-28387

JSON object: View

cve-icon Redhat Information

No data.

CWE