Impact
The Datadog Android app contains an activity that is exported without any permission guard. When launched by a third‑party application, the activity accepts attacker‑controlled extras that can be rendered as lock‑screen text, trigger an on‑call acknowledgement to the Datadog backend using the victim’s authenticated session, or start arbitrary non‑exported components within the app. A single user tap unlocks the screen and surfaces the supplied activity. The outcome is a combination of social engineering, unsolicited network requests, and potential misuse of the Datadog on‑call workflow.
Affected Systems
Datadog Android App (any installed version; specific build numbers not disclosed).
Risk and Exploitability
The vulnerability is exploitable only on devices with the Datadog app installed and a user who is currently logged in. A malicious co‑installed application can invoke the activity directly, bypassing permission checks. Because the attack permits the attacker to send forged acknowledgements over the victim’s credentials, the risk is significant. No EPSS data or KEV listing is available, but the lack of a permission guard implies a high exploitability within the local device context.
OpenCVE Enrichment