Vulnerabilità · 110 giorni fa
L’app mobile di Yarbo e il backend cloud trattano una credenziale come accesso all’intera flotta. Questo significa che estrarre un secret da qualsiasi app binary non è una perdita a livello utente; è un problema del control plane per ogni robot connesso al servizio.
1 fonte che coprono questa storia
Yarbo Android/iOS Mobile Application and Cloud Infrastructure | CISA
Yarbo Android/iOS Mobile Application and Cloud Infrastructure Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain hard-coded credentials, gain access to telemetry data, and potentially send operational commands to the robot fleet.
Part of the PlainSec briefing for 2026-06-12