PT-2026-69088 · Datadog · Datadog Android Application
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Datadog Android application versions prior to 545-5.9.2
Description
Six App Widget configuration activities—IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, and DashboardWidgetActivity—are exported without a permission guard. These activities use a caller-supplied
AppWidgetManager.EXTRA APPWIDGET ID to load a stored session and automatically log in as the user when no deep-link destination is resolved. Since Android widget IDs are small sequential integers, a co-installed malicious application can brute-force this value to identify a widget configured on the victim's device. If a match is found, the activity opens in the foreground under the victim's session, rendering live infrastructure data. This creates a visual side channel where data can be exposed via screen recording, accessibility services, or screenshot capture, although the calling application cannot programmatically read the data.Recommendations
Update Datadog Android application to version 545-5.9.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datadog Android Application