Vulnerabilità ed exploit · Furto di credenziali
L’app mobile di Yarbo e il backend cloud trattano una credenziale come accesso all’intera flotta. Questo significa che estrarre un secret da qualsiasi app binary non è una perdita a livello utente; è un problema del control plane per ogni robot connesso al servizio.
1 fonte · 11 giu
CISA Advisories
Yarbo Android/iOS Mobile Application and Cloud Infrastructure | CISA
Yarbo Android/iOS Mobile Application and Cloud Infrastructure Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain hard-coded credentials, gain access to telemetry data, and potentially send operational commands to the robot fleet.
originalePart of the PlainSec briefing for 2026-06-11
Every edition of this story: Credenziali condivise mettono le flotte Yarbo sotto un’unica chiave