CVE-2026-13514: Chess Play and Learn App Backup File Exposure (Android, Physical Access)
Chess Play and Learn App for Android (versions up to 4.9.42) contains a security flaw in how it handles backup files specified in its AndroidManifest.xml configuration. An attacker with physical access to a device can potentially expose sensitive backup data that should remain protected. While the flaw is real and a proof-of-concept has been publicly disclosed, exploitation requires direct hands-on access to the device itself, which significantly limits the attack surface in most enterprise and personal use scenarios.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 2.4 LOW · CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-285, CWE-530
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-29 / 2026-06-29
NVD description (verbatim)
A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file to an unauthorized control sphere. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be used for attacks. Upgrading the affected component is advised. The vendor was informed early about this issue. They confirmed the existence and that they will address it. Furthermore, they explain that their bug bounty "explicitly excludes physical-access attacks". However, they appreciate the quality of the report and aim at making a goodwill payment to the researcher.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from improper access controls on backup files referenced in the AndroidManifest.xml of the Chess Play and Learn App's com.chess component (CWE-285: Improper Authorization; CWE-530: Use of Insufficiently Random Values or Insufficient Entropy). The flaw allows unauthorized disclosure of backup data when an attacker has physical device access. The CVSS 3.1 score of 2.4 (LOW) reflects the requirement for physical proximity (AV:P) and the confidentiality impact limited to backup exposure, with no integrity or availability consequences. Public exploit code is available, though its practical utility depends on attacker access to unlocked or compromised devices.
Business impact
For most organizations, the business risk is contained because the attack vector requires physical device possession. Mobile device management (MDM) policies that enforce device locks and remote wipe capabilities substantially mitigate this risk. However, users with sensitive data stored in app backups—particularly financial or personal information—face localized exposure if their device is lost, stolen, or borrowed without proper security measures. The goodwill offer from the vendor suggests they view this as a quality-of-life fix rather than a critical security breach, though timely patching remains prudent.
Affected systems
Chess Play and Learn App on Android, all versions through 4.9.42. The vulnerability is specific to this application and does not affect other chess applications or Android itself. Users running version 4.9.43 or later (verify against vendor advisory) are not affected.
Exploitability
Public proof-of-concept code exists, lowering the bar for technical exploitation. However, the attack is feasible only on physical devices under attacker control—an attacker must have direct access to the device, potentially unlock it or access the file system, and extract backup files. This is not a remote vulnerability and cannot be weaponized for mass attacks or lateral movement across networks. The practical threat is limited to scenarios involving device theft, loss, or physical compromise.
Remediation
Users should upgrade Chess Play and Learn App to the patched version released by the vendor (verify the exact version against the official app store or vendor advisory). Organizations managing mobile devices should ensure MDM policies mandate app updates and enforce device-level controls such as screen locks, encryption, and remote wipe capabilities. Until patching, users should avoid storing highly sensitive information in app backup locations and ensure devices remain physically secured.
Patch guidance
Check the Google Play Store or the vendor's official repository for an available update to Chess Play and Learn App. The vendor has confirmed they will address the issue and has provided security updates. Install any version newer than 4.9.42 (verify the exact remediated version in the official advisory). Organizations using EMM/MDM should configure automatic app updates for this application to reduce manual patching overhead.
Detection guidance
On-device detection is impractical because the vulnerability requires physical access and file system-level inspection. Organizations should focus on audit controls: review MDM logs to confirm all managed devices are running a patched version of Chess Play and Learn App; audit device inventory to identify any devices still on version 4.9.42 or earlier; and enforce MDM policies that require app updates within a defined window. Network-level detection is not applicable because this is not a network-exploitable flaw.
Why prioritize this
Although a public exploit exists and the vulnerability is confirmed, the physical-access-only requirement substantially reduces its priority in most threat models. Prioritize patching for organizations with high-risk user populations (e.g., those handling sensitive data), field personnel with devices at elevated theft risk, or environments where device security cannot be guaranteed. For standard office environments with enforced MDM and device management, this is a routine, lower-priority update. Avoid treating it as a critical emergency patch.
Risk score, explained
The CVSS 3.1 LOW score (2.4) accurately reflects the attack vector constraint. The AV:P designation means the flaw requires physical proximity—a rare and high-friction requirement in most cyber threat scenarios. The confidentiality impact is limited (C:L) to backup file exposure, with no ability to modify or disrupt service (I:N, A:N). The low complexity (AC:L) and lack of privilege requirements (PR:N, UI:N) mean that once an attacker has the device, exploitation is straightforward, but the barrier to reaching that point is high. This produces a credibly low numerical score despite the availability of public exploit code.
Frequently asked questions
Does this vulnerability affect all Android devices or only Chess Play and Learn App users?
Only devices with Chess Play and Learn App installed (versions up to 4.9.42) are affected. The flaw is specific to this application and does not impact other Android apps, the Android operating system, or devices without the app.
Can this vulnerability be exploited remotely over the internet or local network?
No. The attack requires physical access to the device. It cannot be exploited remotely, does not spread over networks, and does not enable compromise of other devices or systems.
What should organizations prioritize—patching this immediately or handling it in a routine cycle?
If your organization enforces strong MDM controls (screen locks, encryption, remote wipe) and users do not rely on Chess Play and Learn App for sensitive data, handle it as a routine update during your normal patch window. If users work in high-risk environments or manage sensitive data through the app, prioritize it higher but not necessarily as a critical emergency.
Why did the vendor mention excluding physical-access attacks from their bug bounty if they're still fixing this?
The vendor's bug bounty policy explicitly excludes physical-access scenarios as out-of-scope because they are rarely relevant to real-world security at scale. However, the researcher demonstrated exceptional rigor, so the vendor chose to fix the flaw and offer a goodwill payment. This reflects responsible disclosure practice even when a flaw falls outside typical threat models.
This analysis is provided for informational purposes and reflects publicly available information as of the publication date. The CVSS score, affected versions, and patch status are sourced from the official vulnerability record. Organizations should verify patch availability and version numbers directly with the vendor or official app stores before deploying updates. Physical-access vulnerabilities present lower organizational risk than remote-exploitable flaws, but security posture should be assessed within the context of your specific threat model, MDM capabilities, and data sensitivity. This advisory does not constitute legal or compliance advice. Source: NVD (public-domain), retrieved 2026-08-07. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12065LOWGroww Android App Custom URL Scheme Authorization Bypass
- CVE-2026-13490LOWGLPI Document Authorization Bypass Vulnerability
- CVE-2026-13511LOWVoltAgent Memory REST API Authorization Bypass Vulnerability
- CVE-2026-40963LOWApache Airflow Unauthorized DAG Metadata Disclosure
- CVE-2026-47713LOWAnythingLLM Pre-Migration Token Privilege Escalation & Data Exposure
- CVE-2026-59226LOWOpen WebUI Deactivated User Automation Execution Flaw
- CVE-2026-0072HIGHAndroid XR InputMethodManagerService Privilege Escalation (CVSS 7.8)
- CVE-2026-10070MEDIUMmacrozheng mall Admin Authorization Bypass in /admin/update/