Impact
The CVE exposes a flaw where the com.meesho.supply component of the Meesho Online Shopping App mishandles user‑supplied parameters such as user_id, phone number, email address, and name. This misuse allows the application to write these values to persistent storage in an unencrypted form, a violation of CWE‑310 (Sensitive Data Exposure) and CWE‑312 (Cleartext Storage of Sensitive Information). An attacker who can influence these arguments can cause the device to permanently record personal data in plain text, which any local or physically compromised user could later read.
Affected Systems
Affected version set includes all builds of the Meesho Online Shopping App released up to 2026‑06‑07 on Android. No specific sub‑versions are listed beyond this date marker, so any installation of the app on Android that contains the com.meesho.supply module is considered vulnerable. The vendor is Meesho and the product is the Meesho Online Shopping App.
Risk and Exploitability
The CVSS base score of 2.4 indicates low severity, and the EPSS score is less than 1%, indicating a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local to the physical device; an attacker must manipulate the argument values directly on the handheld device. Although the flaw does not grant remote code execution or system compromise, once the data is written it can be retrieved by anyone with physical or local access to the device.
OpenCVE Enrichment