Description
A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file res/raw/app.json of the component co.gridapp.organiser. Performing a manipulation of the argument SegmentWriteKey results in use of hard-coded cryptographic key . The attack is only possible with local access. The exploit has been made public and could be used.
Problem types
Use of Hard-coded Cryptographic Key
Product status
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
Timeline
| 2026-04-02: | VulDB entry created |
| 2026-04-03: | Advisory disclosed |
| 2026-04-03: | VulDB entry last update |
Credits
fxizenta (VulDB User)
References
vuldb.com/vuln/355042 (VDB-355042 | GRID Organiser App co.gridapp.organiser app.json hard-coded key)
vuldb.com/vuln/355042/cti (VDB-355042 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/781759 (Submit #781759 | GRID GmbH GRID ORGANISER(co.gridapp.organiser) 1.0.5 Segment Write Key Exposure)
www.notion.so/...3f97fb801b9173c4851c7ad864?source=copy_link