Executive brief
Splashin is a mobile application for iOS that provides location-based services. A vulnerability in version 2.0 allows users on the free tier to bypass intended restrictions on how frequently they can update their location. This could lead to increased server load or service degradation, potentially impacting the availability of the platform for other users.
Technical details
The Splashin iOS application (v2.0) contains a logic flaw where server-side rate limiting or interval enforcement for location updates is missing for users on the free subscription tier. An attacker can programmatically send location update requests at a higher frequency than intended by the service provider. This is a network-based attack that requires no special privileges or user interaction. The primary impact is a partial loss of availability (DoS) due to potential resource exhaustion on the backend infrastructure.
Affected products
- Splashin Splashin iOS 2.0
Timeline
- 2025-07-18: advisory: NVD publication date
- 2025-07-18: disclosed: Initial CVE assignment and description added