Intel

AIKIDO-2025-10027

BrazeUI is vulnerable to Incorrect Authorization

Incorrect Authorization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 20, 2025

20

Low Risk

This Affects:

swiftBrazeUI
5.0.0 - 11.4.0
Fixed in 11.5.0
Are you affected? Scan for Free

TL;DR

Affected versions are vulnerable to incorrect authorization, allowing an in-app message in a Braze-provided UI to display for an ineligible user under rare conditions. This issue occurs when an in-app message is in the process of being displayed while the user is switched to a different user within the application.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

BrazeUI is vulnerable to Incorrect Authorization in versions 5.0.0 - 11.4.0.

How to fix this

Upgrade the BrazeUI library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform