CVE-2024-38480: Kakao Piccoma Corp Piccoma App For Android
Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.
"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability.
Affected products
- Kakao Piccoma Corp Piccoma App For Android: before 6.20.0 (fixed in 6.20.0)
- Kakao Piccoma Corp Piccoma App For IOS: before 6.20.0 (fixed in 6.20.0)
Published 2024-07-01. Last modified 2026-06-17.