CVE-2026-85153
Received
Received - Intake
Hardcoded Credentials and Cryptographic Keys in Schmooze App
Vulnerability report for CVE-2026-85153, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: Indian Computer Emergency Response Team (CERT-In)
Description
Description
This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys.
Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Schmooze | Schmooze | dating mobile Application Android versions 5.2.7 (build 452) and prior |
| Schmooze | Schmooze | dating mobile Application iOS versions 5.2.1 and prior |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |