Security Flaws Exposed in QuickBlox Chat And Video Framework
ID: e81e3964-68e2-5a8b-9443-948cc0f93221
STIX ID: report--e81e3964-68e2-5a8b-9443-948cc0f93221
Feed Name: Claroty Team82
Date Published: 2023-10-30
Date Updated: 2026-04-17
Author: Amir Preminger; Sharon Brizinov; Itay Cohen; Oleg Ilushin
Team82 and Check Point Research analyzed the QuickBlox SDK/API and discovered critical design flaws that expose application secrets and allow attackers to enumerate and exfiltrate user databases, create accounts, and take over sessions; they demonstrated these issues in proofs-of-concept against smart intercom (Rozcom) and a telemedicine app, enabling remote door opening, camera/microphone access, and mass leakage of patient PII; QuickBlox collaborated to remediate the vulnerabilities and released a redesigned, more secure API.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
