Executive brief
The Rico investment application for Android contains a security flaw where a sensitive cryptographic key is hard-coded within the app's source code. An attacker with local access to the device could potentially extract this key to intercept or manipulate data related to the app's analytics and user tracking. This could lead to the exposure of user profile information or the injection of fraudulent data into the service's backend.
Technical details
A vulnerability classified as CWE-321 (Use of Hard-coded Cryptographic Key) exists in the Rico Android application up to version 4.58.32.12421. The flaw is located in the 'SEGMENT_WRITE_KEY' argument within the 'br/com/rico/mobile/di/SegmentSettingsModule.java' file. A local attacker can extract this hard-coded key from the application package. Possession of this key allows for unauthorized data injection and potential manipulation of user profile data within the Segment analytics framework used by the app. As of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- Rico só vantagem pra investir App up to 4.58.32.12421
Timeline
- 2026-04-03: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-04-03: advisory