Executive brief
Capgo is a mobile app update management platform that controls which versions of applications are delivered to devices. An attacker with API write permissions can bypass content-integrity protections by keeping bundle versions in an incomplete state, then modifying critical metadata like checksums and encryption keys before the version is delivered to devices. This allows tampering with app updates without detection, potentially enabling malware distribution or application compromise.
Technical details
The vulnerability stems from a flawed content-lock trigger that exempts rows with storage_provider='r2-direct' from mutation protection, combined with the /updates endpoint failing to filter out such rows when selecting versions for delivery. An authenticated attacker with bundle upload permissions can create or retain a version in the r2-direct state, assign it to a distribution channel, then mutate delivery-critical fields (checksum, session_key, name, app_id, r2_path, external_url, manifest, native_packages) via direct database requests. The changes are served to devices through /updates without validation, bypassing previous metadata-tampering mitigations.
Affected products
- Cap-go capgo all
Timeline
- 2026-09-26: disclosed
- 2026-09-09: advisory: GitHub Security Advisory GHSA-5rg9-rhwj-wj76 published