PT-2026-69088 · Datadog · Datadog Android Application

·

CVE-2026-44965

·

Published

2026-08-07

·

Updated

2026-08-08

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Datadog Android application versions prior to 545-5.9.2
Description Six App Widget configuration activities—IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, and DashboardWidgetActivity—are exported without a permission guard. These activities use a caller-supplied AppWidgetManager.EXTRA APPWIDGET ID to load a stored session and automatically log in as the user when no deep-link destination is resolved. Since Android widget IDs are small sequential integers, a co-installed malicious application can brute-force this value to identify a widget configured on the victim's device. If a match is found, the activity opens in the foreground under the victim's session, rendering live infrastructure data. This creates a visual side channel where data can be exposed via screen recording, accessibility services, or screenshot capture, although the calling application cannot programmatically read the data.
Recommendations Update Datadog Android application to version 545-5.9.2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44965

Affected Products

Datadog Android Application