Potentially tampered sources on Play Store for Chameleon Mini Live Debugger
No sign of exploitation. No public exploitation artifact known so far.
A malicious actor may have tampered with the Chameleon Mini Live Debugger app (version 1.1.6-free) on Google Play Store, potentially injecting harmful code or requesting dangerous permissions. Users should immediately update to version 1.1.8 or later to ensure their device is not compromised.
CWE-506 describes supply chain compromise where application sources or permissions may have been altered by an unauthorized third party in the official distribution channel. The attack vector is installation of a tampered binary from the Play Store; the impact includes potential arbitrary code execution and unauthorized access to device resources depending on what malicious modifications were introduced.