Authentication Bypass in Schmooze App by Schmooze Technologies
CVE-2026-85153

9.3CRITICAL

Key Information:

Vendor

Schmooze

Vendor
CVE Published:
6 October 2026

What is CVE-2026-85153?

The Schmooze app has a security vulnerability stemming from hardcoded credentials and cryptographic keys within its client application, allowing unauthenticated remote attackers to exploit this weakness. By decompiling the application package, attackers can extract these embedded credentials and keys, potentially granting them unauthorized access to backend and cloud resources. This exploitation can enable malicious actors to forge client requests, compromising the integrity of the targeted system.

Affected Version(s)

Schmooze dating mobile Application Android versions 5.2.7 (build 452) and prior

Schmooze dating mobile Application iOS versions 5.2.1 and prior

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Nisarga Adhikary and Shriram Dhumal.
.