CVE-2025-61113

7.5

TalkTalk · TalkTalk Android App

The TalkTalk Android application, version 3.3.6, contains improper access control vulnerabilities in multiple API endpoints that allow unauthorized access to sensitive user and group information.

Executive summary

The TalkTalk Android application is vulnerable to unauthorized data disclosure due to improper access controls, posing a significant risk of privacy breaches for users.

Vulnerability

This vulnerability involves improper access control within API endpoints, allowing unauthenticated attackers to modify request parameters to retrieve sensitive user data, such as device identifiers, birthdays, and private group join credentials.

Business impact

The exposure of sensitive user data and private group credentials can lead to severe privacy violations and unauthorized access to restricted customer resources. Given the CVSS score of 7.5, this high severity vulnerability represents a significant risk to organizational reputation and customer trust, necessitating immediate attention to prevent data exfiltration.

Remediation

Immediate Action: Since no patch is currently identified, users and administrators should restrict access to the affected service and monitor the vendor for the release of an updated application version.

Proactive Monitoring: Security teams should review API access logs for anomalous parameter manipulation patterns or unexpected requests originating from mobile clients.

Compensating Controls: Implement robust API gateway controls to validate and sanitize all incoming requests, ensuring that access to sensitive endpoints is strictly enforced regardless of client-side parameters.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.

Analyst recommendation

The severity of this vulnerability, combined with the availability of a public proof-of-concept, necessitates immediate action. Organizations utilizing the TalkTalk Android application must prioritize the mitigation of these API flaws to prevent unauthorized data access. Continue to monitor the official vendor channels for emergency security updates and apply them as soon as they become available.

Sources