View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Chinese Civic Apps Share Vulnerable Reward Backend Allowing Forged

🕵️ RESEARCH & DEEP DIVES

  • Chinese Civic Apps Share Vulnerable Reward Backend Allowing Forged Lottery Claims — neurowinter.com
    Multiple Chinese civic apps use a shared reward backend with a recoverable signing secret enabling forged reward claims.
    • Applies to multiple Chinese civic and government-adjacent apps across Zhejiang and Guangdong prefectures
    • Vulnerability in shared multi-tenant SaaS reward backends from providers like tmuyun, aihoge, jinhua, and Duiba
    • Signing secret intended to secure reward claims is publicly recoverable from client-side code
    • Attackers can forge valid reward claims and lottery wins accepted by backend APIs
    • Forged claims can target daily bonuses, quizzes, sweepstakes, and potentially access citizen PII

🔓 CVEs & KEV

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check