Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-85153— Information Disclosure Vulnerability in Schmooze dating mobile Application

Quick assessment

Affected
Schmooze Schmooze dating mobile Application
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

该漏洞存在于 Schmooze 应用中,原因是客户端应用程序中使用了硬编码的凭据和密码学密钥。未认证的远程攻击者可以通过反编译分发的应用程序包,提取其中嵌入的凭据和密码学密钥来利用此漏洞。 成功利用此漏洞可能使攻击者能够未经授权访问后端和云资源,并在目标系统上伪造客户端请求。

CVSS 9.3 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85153

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Information Disclosure Vulnerability in Schmooze dating mobile Application
Source: CVE Program / CVE List V5
Vulnerability Description
This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的密码学密钥
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Schmooze Schmooze dating mobile Application Android versions 5.2.7 (build 452) and prior -

II. Public POCs for CVE-2026-85153

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85153

请登录查看更多情报信息。

Other References for CVE-2026-85153 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85153

No comments yet


Leave a comment