Impact
The GRID Organiser App (co.gridapp.organiser) contains a hard‑coded cryptographic key in its res/raw/app.json file. By manipulating the SegmentWriteKey argument, a local attacker can force the app to use the embedded key during cryptographic operations. This misuse can undermine the integrity of encrypted data, potentially allowing the attacker to inject or modify information. The vulnerability is a classic key‑management flaw (CWE‑320) and a security flaw involving compromised key usage (CWE‑321).
Affected Systems
Versions of the GRID Organiser App up to 1.0.5 for Android are affected. No other products or newer releases were identified in the advisory. The issue is tied specifically to the co.gridapp.organiser component.
Risk and Exploitability
The CVSS score is 4.8, indicating medium severity. Exploitation is limited to users who have local device access, and the EPSS metric is not available. The vulnerability is not referenced in the CISA KEV catalog. A public exploit demonstrates that the key misuse can be triggered by local manipulation, and while the advisory implies possible data injection or user‑profile changes, that outcome is inferred and not explicitly confirmed in the description.
OpenCVE Enrichment