User Data Association Vulnerability in Datadog Android Application
CVE-2026-47364
6.5MEDIUM
What is CVE-2026-47364?
The Datadog Android application has a vulnerability where, upon every successful login, it associates the user's Datadog UUID with the Firebase installation ID via FirebaseCrashlytics.setUserId. This integration may inadvertently expose user identifiers to Firebase's backend without providing a visible consent mechanism for users. Furthermore, any uncaught exceptions are forwarded to Firebase Crashlytics, potentially including sensitive information in the stack traces related to internal class names and in-flight data. The lack of an opt-out option raises concerns about user privacy and data anonymization.
Affected Version(s)
Android App 5.9.2
