Kidsview App Authentication Bypass Patched
A vulnerability in the Kidsview mobile app let someone with physical device access bypass login and take over the account via push notifications; fixed in version 4.4.3.
CERT Polska coordinated disclosure of CVE-2026-8990, a vulnerability affecting the Kidsview mobile application. The flaw allows an attacker with physical access to a victim's smartphone to bypass the app's authentication mechanism by interacting with a push notification, granting themselves full access to the device owner's account.
The vulnerability requires local physical access rather than remote exploitation, limiting its scale but still posing a risk to users in scenarios such as device theft, loss, or shared access. The issue has been fixed in Kidsview version 4.4.3, and users are advised to update. The report was credited to researcher Jakub Lewandowski through CERT Polska's coordinated vulnerability disclosure process.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8990
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free