Denial of Service Vulnerability in Datadog Android Application
CVE-2026-47361

6.4MEDIUM

Key Information:

Vendor

Datadog

Vendor
CVE Published:
7 August 2026

What is CVE-2026-47361?

The Datadog Android application exposes the BubbleChatActivity with an improperly configured export attribute, allowing unguarded access to SEND intents. This vulnerability permits unauthorized applications to cancel the Bits AI chat notification on the user's device, exposing them to potential phishing attacks through the disruption of in-app workflows. While there is no data exposure due to server-side authentication, the potential for nuisance and disruption makes this a significant concern for users.

Affected Version(s)

Android App 5.9.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mark Esler
.