PT-2025-50540 · Meatmeet · Meatmeet

Published

2025-12-10

·

Updated

2026-01-06

·

CVE-2025-65832

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Meatmeet (affected versions not specified)
Description The mobile application improperly manages sensitive information stored in memory. A memory dump of the application, following user logout and termination, can reveal Wi-Fi credentials transmitted during pairing, JWTs used for authentication, and other sensitive data. An attacker with physical access to a victim’s device could retrieve this information, potentially gaining unauthorized access to the victim’s home Wi-Fi network and Meatmeet account. The application's handling of JWTs and Wi-Fi credentials during the pairing process is a key aspect of this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-65832

Affected Products

Meatmeet