Junglewise Threat Intelligence

CVE-2026-13514: Chess.com Play and Learn App backup file exposure in AndroidManifest.xml

CVE-2026-13514 · Severity: low · CVSS 2.4 · Published 2026-06-29

Executive brief

A security weakness in the Chess.com Android app allows an individual with physical access to a device to access application backup files. This could lead to the exposure of local app data that is normally protected. The vendor has acknowledged the issue and plans to address it in a future update.

Technical details

A vulnerability classified as Improper Authorization (CWE-285) and Exposure of Backup File (CWE-530) exists in the Chess.com Play and Learn App up to version 4.9.42 on Android. The issue stems from improper configuration within the AndroidManifest.xml file, which fails to restrict backup operations. An attacker with physical access to the device can exploit this to extract application data via the Android backup mechanism. While the vendor's bug bounty program excludes physical-access attacks, they have confirmed the vulnerability and advised users to upgrade once a fix is released. A public exploit has been reported.

Affected products

  • Chess.com Play and Learn App up to 4.9.42

Timeline

  • 2026-06-29: disclosed: Vulnerability disclosed and CVE assigned

References