How mobile app analytics library led to the PII exposure

178 · Cossack Labs · July 25, 2025, 2:15 p.m.
Summary
The blog post discusses a serious security issue involving a third-party analytics library that unintentionally leaked personally identifiable information (PII) from a mobile app. Despite no changes being made by the development team, the library was found to be sending user credentials to its backend, highlighting the importance of security audits and developer awareness.