Nothing Fixed CMF Watch App Vulnerability That Could Expose Email Addresses, s: Report 2c604e

Nothing's CMF Watch app no longer exposes information encrypted in the app and the company will reportedly roll out additional fixes. 444q6p

Nothing Fixed CMF Watch App Vulnerability That Could Expose Email Addresses, s: Report

Photo Credit: CMF by Nothing h63n

The CMF Watch Pro was launched by the Nothing sub brand earlier this year

Highlights
  • Nothing recently partially fixed a security flaw with the CMF Watch app
  • The vulnerability could allow access to a 's name and
  • Nothing says further fixes will be rolled out via an over-the-air update
ment

shut down amid allegations that the service did not encrypt messages and media as d by Nothing and its partner Sunbird.

9to5Google contributor Dylan Roussel, in a recent a thread on X (formerly Twitter), explained that the CMF Watch app was encrypting both the email address and provided by s when g up for an — while allowing decryption of both the email and with the same keys. The publication reports that the means to decrypt information was also found in the Android app, which allowed anyone to view those details.

> So what's the problem? Back in September, the CMF Watch app was encrypting both the email and , which was great!
>
> But the encryption method used also allowed anyone to decrypt the email and with the exact same keys. > > — Dylan Roussel (@evowizz) December 1, 2023

Back in September, Roussel had pointed out that the CMF Watch app was developed by Chinese firm Jingxun, and references to the firm were visible in the app. At the time, he pointed out that the company's website also lists OnePlus as one of its partners, alongside Sony, Philips, and Toshiba.

Months after the vulnerabilities were reported, CMF by Nothing told the publication that it is working to fix the security flaws pointed out by Roussel — the encryption method for a 's has reportedly been resolved, while the email address is still impacted by the flaw. The company told 9to5Google that an OTA update will be rolled out to CMF Watch Pro s to resolve outstanding issues.

According to the 9to5Google report, the company recently opened up different points of for vulnerabilities with both Nothing and CMF by Nothing products — these weren't available back in September when the flaws were being reported.

It is worth noting that Nothing was recently entangled in a privacy controversy when the company released its Nothing Chats app in beta, promising Nothing Phone 2 s access to Apple's proprietary iMessage service. After several issues with the privacy and security of the service were raised online — including handling of unencrypted messages and media by Nothing's partner Sunbird — the company pulled its app from the Play Store, while Sunbird also informed s it was pausing access to its own service.


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
links may be automatically generated - see our ethics statement for details.

CMF Watch Pro 49486o

  • REVIEW
  • KEY SPECS
  • NEWS
  • Design and comfort
  • Tracking accuracy
  • Companion app
  • Software and ecosystem
  • Battery life
  • Good
  • Smooth UI
  • Relatively fast charging
  • Long-lasting battery
  • IP68 dust and water resistance
  • Bad
  • Limited watch faces
  • Buggy companion app
  • No interchangeable watch straps
Strap Colour dark grey, ash grey, orange
Dial Shape Square
Display Type AMOLED
Ideal For Unisex
Comments

For the latest reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Vulnerabilities
David Delima
As a writer on technology with Gadgets 360, David Delima is interested in open-source technology, cybersecurity, consumer privacy, and loves to read and write about how the Internet works. David can be ed via email at [email protected], on Twitter at @DxDavey, and Mastodon at mstdn.social/@delima. More
GTA 6 Trailer Out Now; Will Be Available in 2025, Platforms Confirmed
Crypto Price Today: Bitcoin Continues to See Rise in Value, Most Altcoins See Losses
Facebook Gadgets360 Twitter Share Tweet Snapchat LinkedIn Reddit Comment google-newsGoogle News

ment

Follow Us

ment

© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »