Kidsview auth bypass via push notification
A physical-access flaw in Kidsview mobile app allows local attackers to bypass authentication via push notification interaction, fixed in version 4.4.3.
CERT Polska coordinated disclosure of CVE-2026-8990, an authentication bypass vulnerability in the Kidsview mobile application. The flaw allows an attacker with physical access to a smartphone to circumvent the application's authentication mechanism by interacting with push notifications, thereby gaining full access to the device owner's account.
The vulnerability was responsibly reported by Jakub Lewandowski and has been addressed in Kidsview version 4.4.3. Users of the application should update to the patched version to eliminate this attack vector.
While the vulnerability requires physical device access, limiting its scope, it represents a significant privacy and security risk for users of the parental control application, particularly in scenarios where devices may be temporarily unattended or accessed by unauthorized individuals.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8990
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free