CVE-2026-85153

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed application package and extracting the embedded credentials and cryptographic keys. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to backend and cloud resources and forge client requests on the targeted system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-06: 210-06
Referenced assets1 URL
By indicator
Full discourse2 posts
  • nisarga@ni5arga

    CVE-2026-85153 critical vuln in a dating app i can hack a dating app but still can’t get a girlfriend

    31405774416.1K
    28.6K followersView on X
  • nisarga@ni5arga

    cve record: https://www.cve.org/CVERecord?id=CVE-2026-85153 co-reasearched w/ @0x1622, he's super cool. he has also been credited.

    0002212.4K
    28.6K followersView on X

Explore more