logo

EU’s New Age Verification App Can Be Hacked Within 2 Minutes, Researchers Claim

ID: e8d5b03e-5c1c-5e89-baf8-11f8d26b1080

STIX ID: report--e8d5b03e-5c1c-5e89-baf8-11f8d26b1080

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-04-21

Author: Guru Baran

...
...

The European Commission’s Digital Age Verification App contains critical design flaws: encrypted PINs stored in an editable local shared_prefs file can be reset (deleting PinEnc/PinIV) to allow full authentication bypass, the brute-force counter can be reset to bypass rate limits, and a boolean flag can disable biometric checks. A UK researcher demonstrated a complete authentication bypass in under two minutes, the app is in pilot in several EU states and serves as a prototype for the broader Digital Identity Wallet, and no official patch had been issued as of April 17, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.