PatchSiren

Investory CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Investory CVE published 2026-04-03

CVE-2026-5471

A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android, related to the use of a hard-coded cryptographic key in the assets/google-services-desktop.json file of the app.investory.toyfactory component. The manipulation of the argument current_key results in the use of a hard-coded cryptographic key. The attack must be initiated from a local position. The exploit is now publi [truncated]