Executive brief
The GRID Organiser App for Android contains a security flaw where sensitive configuration keys are hard-coded within the application's files. An attacker with local access to the device could extract these keys, potentially allowing them to manipulate user profiles or inject unauthorized data into the application's analytics stream. This could lead to inaccurate business data or unauthorized modification of user-related information.
Technical details
A vulnerability classified as the use of a hard-coded cryptographic key (CWE-321) exists in the GRID Organiser App (co.gridapp.organiser) up to version 1.0.5 on Android. The 'SegmentWriteKey' is stored in plain text within the 'res/raw/app.json' file. A local attacker with low privileges can extract this key to perform unauthorized data injection or user profile manipulation via the Segment analytics platform. A public exploit (Proof of Concept) has been disclosed. No official patch has been confirmed in the advisory text.
Affected products
- GRID Organiser App up to 1.0.5
Timeline
- 2026-04-03: disclosed
- 2026-04-03: advisory