Description
A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory.toyfactory. The manipulation of the argument current_key results in use of hard-coded cryptographic key . The attack must be initiated from a local position. The exploit is now public and may be used.
Problem types
Use of Hard-coded Cryptographic Key
Product status
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
Timeline
| 2026-04-03: | Advisory disclosed |
| 2026-04-03: | VulDB entry created |
| 2026-04-03: | VulDB entry last update |
Credits
fxizenta (VulDB User)
References
vuldb.com/vuln/355075 (VDB-355075 | Investory Toy Planet Trouble App app.investory.toyfactory google-services-desktop.json hard-coded key)
vuldb.com/vuln/355075/cti (VDB-355075 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/781784 (Submit #781784 | INVESTORY Investory(app.investory.toyfactory) 1.5.5 Firebase API Key Exposure)
www.notion.so/...3f97fb80f1abe6fb5f3eb373bc?source=copy_link