CVE-2026-85153 PUBLISHED

Information Disclosure Vulnerability in Schmooze dating mobile Application

Assigner: CERT-In
Reserved: 03.09.2026 Published: 06.10.2026 Updated: 06.10.2026

This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys.

Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
CVSS Score: 9.3

Product Status

Vendor Schmooze
Product Schmooze dating mobile Application
Versions Default: unaffected
  • Version Android versions 5.2.7 (build 452) and prior is affected
  • Version iOS versions 5.2.1 and prior is affected

Solutions

Upgrade Schmooze to the latest versions:

Android 5.2.8 or later

iOS 5.2.2 or later

Credits

  • This vulnerability is reported by Nisarga Adhikary and Shriram Dhumal. finder

References

Problem Types

  • CWE-321 Use of hard-coded cryptographic key CWE

Impacts

  • CAPEC-191 Read Sensitive Constants Within an Executable