logo

Security Flaws Exposed in QuickBlox Chat And Video Framework

ID: e81e3964-68e2-5a8b-9443-948cc0f93221

STIX ID: report--e81e3964-68e2-5a8b-9443-948cc0f93221

Feed Name: Claroty Team82

Threat Score
80/100

Date Published: 2023-10-30

Date Updated: 2026-04-17

Author: Amir Preminger; Sharon Brizinov; Itay Cohen; Oleg Ilushin

...
...

Team82 and Check Point Research analyzed the QuickBlox SDK/API and discovered critical design flaws that expose application secrets and allow attackers to enumerate and exfiltrate user databases, create accounts, and take over sessions; they demonstrated these issues in proofs-of-concept against smart intercom (Rozcom) and a telemedicine app, enabling remote door opening, camera/microphone access, and mass leakage of patient PII; QuickBlox collaborated to remediate the vulnerabilities and released a redesigned, more secure API.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.