CVE-2026-86443: Cleartext Storage of Sensitive Information Vulnerability
Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DuoxMe (Android)to a version that resolves this vulnerability.Fixed in 4.3.4 - Operational
If DuoxMe credentials were stored prior to upgrading, rotate/revoke any exposed credentials because local attackers could have retrieved them and impersonated the user account.
Event History
Frequently Asked Questions
Who is exposed to credential theft through this issue?
Users running DuoxMe for Android versions earlier than 4.3.4 are exposed if an attacker obtains local access to their device. The attacker can retrieve credentials stored by the application and impersonate the affected user account.
What level of access does an attacker need?
The issue requires local access to the Android device. The available information does not describe a remote exploitation path.
Which versions should be remediated?
DuoxMe for Android versions prior to 4.3.4 are affected. Updating to version 4.3.4 or later addresses the affected version range described.