Audit report published Apr 2025. Android app, wallet API and admin API.
| Severity | Count |
|---|---|
| Critical | 4 |
| High | 7 |
| Medium | 16 |
| Low | 13 |
| Total | 40 |
Safe Edges ran a grey-box penetration test of the Xenea Wallet Android app, its wallet API and its admin endpoint between 26 February and 21 March 2025, using test credentials provided by Xenea. Forty issues were identified: four Critical, seven High, sixteen Medium and thirteen Low. The Critical issues were unauthorized access to the admin API, an IDOR that disclosed other users' information, an insecure broadcast receiver that allowed arbitrary file writes, and sensitive data stored unprotected in a local database. Xenea fixed twenty-seven issues and acknowledged thirteen.
C-01 Unauthorized Access to Admin Api — ResolvedC-02 Unauthorized IDOR leads to Information Disclosure — ResolvedC-03 Insecure Broadcast Receiver Leading to Arbitrary File Write — AcknowledgedC-04 Sensitive Data Stored Unsecured in Local Database Exposes Privacy Risks — ResolvedH-01 SSL Pinning Bypass via Root-Level Certificate Installation and ReFlutter — ResolvedH-02 Improper Implementation of Root and Emulator Detection Mechanisms — ResolvedH-03 IDOR Leading to Account ID and NFT Ticket data Exposure. — ResolvedH-04 Sensitive Data Stored in Android Memory. — ResolvedH-05 Unprotected SQLite Database Susceptible to SQL Injection Attacks — AcknowledgedH-06 Unlocked and Reassigned: Bypassing App Integrity — ResolvedH-07 Session token in URL — ResolvedM-01 Anti hooking not implemented — ResolvedM-02 Improper Input Validation — ResolvedM-03 Application Data can be Backed up — ResolvedM-04 Application logs sensitive information — ResolvedM-05 CBC mode leads to oracle padding attack — ResolvedM-06 Exposed Debugging Symbols in Library — ResolvedM-07 Insecure Random Number Generation Vulnerability in Android App — AcknowledgedM-08 Sensitive information disclosure through auto-generated screenshot — ResolvedM-09 Missing Security Headers — ResolvedM-10 Account lockout not properly configured — AcknowledgedM-11 No rate limit leads to Dos. — ResolvedM-12 PIN History Not Enforced — ResolvedM-13 Public JWKS Exposure — AcknowledgedM-14 Cross-Origin Resource Sharing (CORS) Vulnerable — ResolvedM-15 Session active after logout — ResolvedM-16 Improper use of Printstacktrace function — AcknowledgedL-01 Android Export flag is enabled — AcknowledgedL-02 App can be installed on a vulnerable upatched Android version — ResolvedL-03 App creates temp file — AcknowledgedL-04 Deeplink Misconfiguration Enables Unauthorized Navigation — AcknowledgedL-05 Sensitive Google API Key Leaked in Android App Source Code — ResolvedL-06 Remote Access Tool Detection not properly implemented — ResolvedL-07 Sensitive Data leakage via application screenshot (Screen Caching) — ResolvedL-08 Permission Overload: Dangerous Access Granted — AcknowledgedL-09 Weak Encryption Algorithm Compromises App Data Security — ResolvedL-10 Missing cookie attributes - httponly,secure,SameSite and path set to root — AcknowledgedL-11 Concurrent login allowed — AcknowledgedL-12 JWT injection — AcknowledgedL-13 Disabled X-XSS-Protection Header Leading to Increased XSS Risk — ResolvedSend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.