Executive brief
A security vulnerability exists in the Shinrays Games Goods Triple App, a mobile gaming application. The software uses fixed, hard-coded security keys for its encryption processes. This could allow a person with local access to the device to bypass certain security protections or access sensitive data that was intended to be encrypted.
Technical details
A use of hard-coded cryptographic key (CWE-321) vulnerability exists in Shinrays Games Goods Triple App up to version 1.200. The flaw is located within the jRwTX.java file of the cats.goods.sort.sorting.games component, specifically involving the AES_IV and AES_PASSWORD arguments. An attacker with local access to the system can retrieve these hard-coded credentials to decrypt sensitive information. The attack complexity is high, requiring specific knowledge of the application's internal structure, and a public exploit has been released. No patch is currently available as the vendor did not respond to disclosure attempts.
Affected products
- Shinrays Games Goods Triple App up to 1.200
Timeline
- 2026-04-02: disclosed: Public disclosure via VulDB and NVD
- 2026-04-02: advisory
- 2026-04-03: other: CISA-ADP assessment added to record