Executive brief
A vulnerability exists in the Dialogue App for Android where sensitive configuration data is stored insecurely. Specifically, a hard-coded key used for data tracking and analytics is exposed within the application's files. A local attacker or a malicious app on the same device could potentially use this key to inject fraudulent data or manipulate user profile information within the analytics platform.
Technical details
A vulnerability (CWE-321) exists in the Dialogue App (ca.diagram.dialogue) up to version 4.3.2 on Android. The file 'res/raw/config.json' contains a hard-coded 'SEGMENT_WRITE_KEY'. An attacker with local access to the device or a malicious application with local permissions can extract this key. This exposure allows for the unauthorized injection of data or manipulation of user profiles within the Segment analytics environment associated with the app. The vendor has reportedly not responded to disclosure attempts, and a proof-of-concept has been publicly disclosed.
Affected products
- Dialogue Dialogue App up to 4.3.2
Timeline
- 2026-04-03: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-04-03: advisory: CVE-2026-5455 published.