PT-2026-69092 · Datadog · Datadog Android Application
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Datadog Android application versions prior to 545-5.9.2
Description
The application associates the user's Datadog UUID—a stable per-user identifier—with the device's Firebase installation ID on Google's backend by calling
FirebaseCrashlytics.setUserId upon successful login. Uncaught exceptions are then forwarded to Firebase Crashlytics via the recordException() function, attaching stack traces and breadcrumbs to that same UUID. This process occurs without a visible consent gate or user-facing opt-out mechanism, making the UUID and crash data visible within Firebase Crashlytics.Recommendations
Update the Datadog Android application to version 545-5.9.2 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datadog Android Application