CVE-2026-5453
A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processi
CVSS
3.3
Low
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: Apr 3, 2026 · Last modified: Jul 24, 2026 · CWE-320 · CWE-321
A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads to use of hard-coded cryptographic key . The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- vuldb.comhttps://vuldb.com/submit/781758
- vuldb.comhttps://vuldb.com/vuln/355041
- vuldb.comhttps://vuldb.com/vuln/355041/cti
- www.notion.sohttps://www.notion.so/Segment-Write-Key-Exposure-Leading-to-Data-Injection-and-User-Profile-Manipulation-In-br-com-rico-mo-3262de3f97fb800a9bfef6e6fd7d7179?source=copy_link