Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
EU’s Digital Age App Vulnerable to Quick Hacking

EU’s Digital Age App Vulnerable to Quick Hacking

Posted on April 17, 2026 By CWS

The European Commission’s latest Digital Age Verification App, designed to protect young users from inappropriate online content, has been swiftly compromised. Security expert Paul Moore, based in the UK, demonstrated a complete bypass of the app’s authentication process in less than two minutes following its release on April 14, 2026.

Security Flaws in App Design

When users set up the app, they are required to create a personal identification number (PIN). This PIN is encrypted and stored on the user’s device in a file called shared_prefs. However, researchers identified two significant design flaws. The PIN encryption is not linked to the identity vault containing the user’s verification credentials, and the encryption method used does not effectively protect against tampering.

An attacker with physical access to a device can manipulate this by removing the PinEnc and PinIV values from the shared_prefs file. After restarting the app, they can set a new PIN, subsequently gaining access to the original user’s verified credentials without raising alarms.

Additional Vulnerabilities Discovered

In addition to the PIN issue, researchers found two more security weaknesses within the same file. The app’s brute-force protection, intended to limit incorrect PIN attempts, is merely an incrementing counter in shared_prefs. An attacker can reset this counter, allowing limitless PIN guesses without any lockout.

Furthermore, the app’s biometric authentication can be bypassed by altering a boolean flag named UseBiometricAuth. By setting this flag to false, attackers can entirely skip the biometric verification step, eliminating an important layer of security.

Implications and Official Response

Experts have labeled these vulnerabilities as severe design failures rather than isolated incidents. The app is intended as a prototype within the broader European Digital Identity Wallet framework, highlighting the significance of these security concerns for essential national infrastructures.

Critics also pointed out another flaw discovered in March 2026, where the app failed to confirm whether passport validation happened on the user’s device. Moore addressed EU Commission President Ursula von der Leyen, cautioning that without intervention, the app could lead to substantial data breaches.

Despite these revelations, as of April 17, 2026, the European Commission has not released an official fix or response to these vulnerabilities. Meanwhile, countries like France, Spain, and Denmark continue testing the app in pilot phases.

For ongoing updates on cybersecurity and more information, follow us on Google News, LinkedIn, and X. Contact us to share your insights and stories.

Cyber Security News Tags:age verification, app security, biometric authentication, Cybersecurity, digital identity, Encryption, EU, Hacking, security flaws, Technology

Post navigation

Previous Post: Apache ActiveMQ Vulnerability Exploited, Urgent Fix Advised

Related Posts

Threat Actors Weaponizing SVG Files to Embed Malicious JavaScript Threat Actors Weaponizing SVG Files to Embed Malicious JavaScript Cyber Security News
Linux 6.16-rc4 Released With Fixes for Filesystem, Driver & Hardware Support Linux 6.16-rc4 Released With Fixes for Filesystem, Driver & Hardware Support Cyber Security News
OPPO Clone Phone Weak WiFi Hotspot Exposes Sensitive Data OPPO Clone Phone Weak WiFi Hotspot Exposes Sensitive Data Cyber Security News
Microsoft to End Support for Windows Server 2016 and Windows 10 Microsoft to End Support for Windows Server 2016 and Windows 10 Cyber Security News
CISA Warns of Dassault Systèmes Vulnerabilities Actively Exploited in Attacks CISA Warns of Dassault Systèmes Vulnerabilities Actively Exploited in Attacks Cyber Security News
Critical GNU InetUtils Vulnerability Allows Unauthenticated Root Access Via “-f root” Critical GNU InetUtils Vulnerability Allows Unauthenticated Root Access Via “-f root” Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • EU’s Digital Age App Vulnerable to Quick Hacking
  • Apache ActiveMQ Vulnerability Exploited, Urgent Fix Advised
  • Nginx UI Flaw Poses Major Security Threat
  • PowMix Botnet Targets Czech Workforce with Stealth Tactics
  • Critical Cisco Webex Flaw Enables User Impersonation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • EU’s Digital Age App Vulnerable to Quick Hacking
  • Apache ActiveMQ Vulnerability Exploited, Urgent Fix Advised
  • Nginx UI Flaw Poses Major Security Threat
  • PowMix Botnet Targets Czech Workforce with Stealth Tactics
  • Critical Cisco Webex Flaw Enables User Impersonation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark