Qardio Arm iOS App Authentication Bypass via Sensitive Data Exposure
The Qardio Arm iOS application exposes sensitive data such as usernames
and passwords in a plist file. This allows an malicious user to log in to
production-level development accounts and access an engineering backdoor
in the application. The engineering backdoor allows the malicious user to
send hex-based commands over a UI-based terminal.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
qardio heart health ios mobile application |