logo

Jamf Threat Labs uncovers mobile app game leaking player credentials

ID: 215bf6b4-2ada-5800-a0fd-ed4675d291a4

STIX ID: report--215bf6b4-2ada-5800-a0fd-ed4675d291a4

Feed Name: Jamf Blog

Threat Score
50/100

Date Published: 2025-11-05

Date Updated: 2026-07-16

...
...

Jamf Threat Labs discovered that World of Warships Blitz (Android and iOS) transmitted obfuscated but replayable login credentials and session cookies to an unencrypted endpoint during login/registration, allowing attackers who capture the traffic to perform replay-based account takeovers; the developer patched the issue in version 8.4.0 following responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.