Authentication Bypass in Schmooze App by Schmooze Technologies
CVE-2026-85153
9.3CRITICAL
What is CVE-2026-85153?
The Schmooze app has a security vulnerability stemming from hardcoded credentials and cryptographic keys within its client application, allowing unauthenticated remote attackers to exploit this weakness. By decompiling the application package, attackers can extract these embedded credentials and keys, potentially granting them unauthorized access to backend and cloud resources. This exploitation can enable malicious actors to forge client requests, compromising the integrity of the targeted system.
Affected Version(s)
Schmooze dating mobile Application Android versions 5.2.7 (build 452) and prior
Schmooze dating mobile Application iOS versions 5.2.1 and prior
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Nisarga Adhikary and Shriram Dhumal.
