The Meesho Online Shopping App for Android, up to version 20260607, contains a vulnerability in the com.meesho.supply component, leading to cleartext storage of sensitive information such as user_id, phone number, email address, and name. This vulnerability can be exploited directly on the physical device, potentially allowing unauthorized access to sensitive information. The attack can be executed direct [truncated]
A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is told to be difficult. This vulnerability has significant oper [truncated]