Impact
The Datadog Android app includes a flaw that tags crash reports sent to Firebase Crashlytics with the user’s stable Datadog UUID, without providing a way for the user to opt out. Because the UUID is not publicly linked to other user data, the impact is limited to the disclosure of a stable identifier that could be used to link Crashlytics events to a specific user. The weakness is categorized as information disclosure (CWE‑200).
Affected Systems
Affecting the Datadog Android application, all releases prior to version v545‑5.9.2 are susceptible. Users who have installed those versions and allow Firebase Crashlytics to send crash data are at risk. The issue is present in every build that contains the Firebase Crashlytics integration and does not include an opt‑out mechanism for the UUID.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No exploit vector or public exploit has been recorded, and the EPSS score is not available, which suggests a lower likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need access to Firebase Crashlytics logs to utilize the exposed UUID, so the threat is primarily privacy‑related rather than a direct compromise of code or data integrity.
OpenCVE Enrichment