CVE-2024-10748: low-severity vulnerability in Cosmote Greece What's Up App
Cosmote Greece What's Up App Realm Database RealmDB.java default key
Published
No sign of exploitation. No public exploitation artifact known so far.
The Cosmote Greece What's Up App uses a default encryption key for its local database, which could allow someone with access to the device to read stored data more easily. This is a low-risk issue because it requires physical access to the phone and is difficult to exploit.
The Realm Database handler in gr/desquared/kmmsharedmodule/db/RealmDB.java uses a hardcoded or predictable default cryptographic key (defaultRealmKey) instead of a unique key, enabling local attackers with device access to decrypt the database. Exploitation requires high complexity and device-level access, but reduces the confidentiality protection of stored sensitive data.