CVE-2026-47361
Received Received - Intake

Bits AI Chat Notification Cancellation in Datadog Android App

Vulnerability report for CVE-2026-47361, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-08

Assigner: HackerOne

Description

In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI chat notification), with no check on the caller's identity or ownership of the conversation. This requires a malicious application co-installed on the victim's device. Impact: A co-installed application can silently dismiss the victim's Bits AI chat notification. No chat content is exposed; conversation data remains server-authentication gated and is never returned to the caller.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-08
Generated
2026-08-28
AI Q&A
2026-08-07
EPSS Evaluated
2026-08-26
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
datadog android_application *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-926 The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Datadog Android app's BubbleChatActivity, which is set to accept external intents without proper permission checks. A malicious app can send a crafted intent to cancel the Bits AI chat notification by supplying a random conversation ID. The activity lacks validation, allowing any app to trigger notification dismissal.

Detection Guidance

This vulnerability is specific to the Datadog Android application and involves an exported activity that can be triggered by any co-installed app. Detection would require checking if the Datadog app is installed and inspecting its manifest for the vulnerable BubbleChatActivity with android:exported="true" and no permission guard.

Impact Analysis

The main impact is denial of the Bits AI chat notification, which could disrupt workflows and potentially aid phishing attempts. No data is exposed, and the attack requires a co-installed malicious app. The effect is limited to notification removal for a specific conversation ID.

Compliance Impact

This vulnerability does not directly cause data exposure or unauthorized access to sensitive information, so it is unlikely to directly violate GDPR or HIPAA. However, it could indirectly impact compliance by disrupting user workflows or enabling phishing attacks within the app, which may undermine security controls required by these regulations.

Mitigation Strategies

Uninstall the Datadog Android application if you do not need it. If the app is required, check for updates from the vendor that may patch this issue. Avoid installing untrusted applications alongside trusted ones to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47361. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart