Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.0

CityData CityChat Android: Unprotected Storage of Credentials

CVE-2026-4251
Summary

The CityData CityChat app on Android stores sensitive credentials in an unprotected file. This means that if someone gains access to your device, they could potentially access your login information and other sensitive data. Update the app to the latest version to fix this issue.

Original title
A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets/assets/credential...
Original description
A vulnerability was determined in CityData CityChat up to 0.12.6 on Android. Affected by this vulnerability is an unknown functionality of the file resources/assets/flutter_assets/assets/credentials.json of the component ai.citydata.citychat. Executing a manipulation can lead to unprotected storage of credentials. The attack requires local access. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 1.0
nvd CVSS3.1 2.5
nvd CVSS4.0 2.0
Vulnerability type
CWE-255
CWE-256
Published: 16 Mar 2026 · Updated: 16 Mar 2026 · First seen: 16 Mar 2026