Critical authentication bypass vulnerabilities in Wondershare RepairIt expose user data and AI models
Summary
Hide β²
Show βΌ
Two critical authentication bypass vulnerabilities in Wondershare RepairIt, an AI-powered data repair and photo editing application, were disclosed. These flaws expose private user data and AI models, potentially allowing attackers to execute arbitrary code on customers' endpoints. The vulnerabilities, CVE-2025-10643 and CVE-2025-10644, have CVSS scores of 9.1 and 9.4, respectively. The issues stem from overly permissive cloud access tokens embedded in the application's code, which enable read and write access to sensitive cloud storage. The data is stored without encryption, and the exposed cloud storage contains AI models, software binaries, container images, scripts, and company source code. This exposure could facilitate supply chain attacks and AI model tampering. Trend Micro researchers disclosed the vulnerabilities in April 2025 but have not received a response from Wondershare. Users are advised to restrict interaction with the product until a fix is available.
Timeline
-
24.09.2025 16:55 π° 1 articles Β· β± 1h ago
Critical authentication bypass vulnerabilities in Wondershare RepairIt disclosed
Two critical authentication bypass vulnerabilities in Wondershare RepairIt were disclosed. These flaws, CVE-2025-10643 and CVE-2025-10644, expose private user data and AI models, potentially allowing attackers to execute arbitrary code on customers' endpoints. The vulnerabilities stem from overly permissive cloud access tokens embedded in the application's code, which enable read and write access to sensitive cloud storage. The exposed cloud storage contains AI models, software binaries, container images, scripts, and company source code, facilitating supply chain attacks and AI model tampering. Trend Micro disclosed the vulnerabilities in April 2025 but has not received a response from Wondershare. Users are advised to restrict interaction with the product until a fix is available.
Show sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
Information Snippets
-
CVE-2025-10643 is an authentication bypass vulnerability in Wondershare RepairIt with a CVSS score of 9.1.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
-
CVE-2025-10644 is an authentication bypass vulnerability in Wondershare RepairIt with a CVSS score of 9.4.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
-
The vulnerabilities allow attackers to bypass authentication and execute arbitrary code on customers' endpoints.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
-
The flaws stem from overly permissive cloud access tokens embedded in the application's code.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
-
The exposed cloud storage contains AI models, software binaries, container images, scripts, and company source code.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
-
The data is stored without encryption, increasing the risk of data breaches and supply chain attacks.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
-
Trend Micro disclosed the vulnerabilities in April 2025 but has not received a response from Wondershare.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55
-
Users are advised to restrict interaction with Wondershare RepairIt until a fix is available.
First reported: 24.09.2025 16:55π° 1 source, 1 articleShow sources
- Two Critical Flaws Uncovered in Wondershare RepairIt Exposing User Data and AI Models β thehackernews.com β 24.09.2025 16:55