Junglewise Threat Intelligence

CVE-2026-5471: Investory Toy Planet Trouble App hard-coded key in assets

CVE-2026-5471 · Severity: low · CVSS 3.3 · Published 2026-04-03

Executive brief

The Toy Planet Trouble mobile application for Android contains a security flaw where sensitive credentials are stored directly within the app's code. An attacker with local access to the device could extract these hard-coded keys, potentially leading to unauthorized access to backend services or data. This could compromise the privacy of user information or allow unauthorized use of the app's cloud resources.

Technical details

A vulnerability (CWE-321) exists in the Investory Toy Planet Trouble App up to version 1.5.5 on Android. The application includes hard-coded cryptographic keys or API credentials within the 'assets/google-services-desktop.json' file. An attacker with local access to the device or the application package can extract these credentials. According to external references, this exposure specifically involves Firebase API keys, which could lead to unauthorized anonymous authentication and data access within the app's backend infrastructure. A public exploit or proof-of-concept is reportedly available.

Affected products

  • Investory Toy Planet Trouble App up to 1.5.5

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References