EU’s New Age Verification App Can Be Hacked Within 2 Minutes, Researchers Claim
ID: ac82b9cc-b6b3-56e4-8f4e-7a3183b9cab3
STIX ID: report--ac82b9cc-b6b3-56e4-8f4e-7a3183b9cab3
Feed Name: Cyber Press
A security researcher reviewed the open-source EU age‑verification app and demonstrated critical flaws in its architecture and cryptography: PINs are encrypted but stored locally and not bound to the identity vault, allowing an attacker with local device access to delete PinEnc/PinIV, reset the PIN, and take over the account; rate‑limiting and biometric authentication flags can likewise be tampered with by editing shared preferences. The findings indicate a systemic insecure design that risks large‑scale exposure of identity credentials and requires a full architectural redesign before deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
