SQL Injection Exposes 62,000 Accounts in Stalkerware App Catwatchful

2025-07-09
SQL Injection Exposes 62,000 Accounts in Stalkerware App Catwatchful

A security researcher discovered a critical SQL injection vulnerability in Catwatchful, an Android spyware app. The vulnerability allowed access to the app's database, revealing plaintext passwords and other user data for approximately 62,000 accounts. Despite the app's claims of invisibility, the researcher easily exploited the vulnerability. While the issue was reported to relevant cloud providers, the service was briefly restored under a new domain before being finally taken down.