We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-41458

Insecure data storage vulnerability in Two App Studio Journey v5.5.9 for iOS



Description

Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.

Reserved 2025-04-16 | Published 2025-07-21 | Updated 2025-07-21 | Assigner cirosec


MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-312 Cleartext Storage of Sensitive Information

Product status

Default status
unknown

Any version
affected

Timeline

2025-03-12:Vendor was contacted and informed about the vulnerability via email.
2025-03-25:Second attempt was made to contact vendor via email.
2025-06-25:Third attempt was made to contact vendor via email.

Credits

Hannes Allmann (cirosec GmbH) <hannes.allmann@cirosec.de> finder

References

www.cirosec.de/sa/sa-2025-005 third-party-advisory

cve.org (CVE-2025-41458)

nvd.nist.gov (CVE-2025-41458)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-41458

Support options

Helpdesk Chat, Email, Knowledgebase