Vulnerability in Flock Safety's Pisco Application for Android Devices
CVE-2025-59406
What is CVE-2025-59406?
The Pisco application by Flock Safety, specifically version 6.21.11 for Android, has been found to contain a cleartext Auth0 client secret within its codebase. This design flaw allows attackers to easily decompile and inspect application binaries, potentially recovering the OAuth secret without any specialized access. As this secret is meant to be kept confidential, its presence in client-side software poses significant risks to the security of the entire system, including the integrity of the Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
