Junglewise Threat Intelligence

CVE-2025-45157: Splashin iOS improper access control in location data

CVE-2025-45157 · Severity: medium · CVSS 6.5 · Published 2025-07-18

Executive brief

Splashin, a mobile application for iOS, contains a security flaw that allows unauthorized individuals to access the location data of its users. This vulnerability stems from improper permission settings within the app's infrastructure. An attacker could exploit this to track specific users without their consent, posing a significant privacy risk and potential threat to user safety.

Technical details

A vulnerability classified as improper access control (CWE-284) exists in Splashin iOS version 2.0. The flaw is rooted in insecure permission settings that fail to adequately restrict access to sensitive user telemetry. A remote, unauthenticated attacker can exploit this weakness over the network to retrieve real-time or historical location data for specific targeted users. The attack does not require user interaction or elevated privileges. While the CVSS score is 6.5 (Medium), the impact is primarily focused on confidentiality and privacy. No official patch information was provided in the advisory.

Affected products

  • Splashin Splashin 2.0

Timeline

  • 2025-07-18: advisory: Initial NVD publication date
  • 2025-07-18: other: CISA-ADP analysis and SSVC enrichment completed

References

Related threats