CVE-2026-103096
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Oct 02, 2026
Vendor
unknown
Description
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.