A Security Researcher Decompiled The White House App, & What They Found Is Pretty Alarming
2026-05-06 13:57 UTC
A security researcher decompiled the White House’s new official app and found some alarming stuff buried in the code, including a hidden GPS tracking pipeline, JavaScript loaded from a random GitHub account, no SSL certificate pinning, and an in-app browser that silently strips cookie consent dialogs and paywalls from every page you visit.
Replies (5)
-
@IAmYouButYouDontKnowYet@reddthat.com 2026-05-06 14:59
None of that is surprising.
-
@Lor@mander.xyz 2026-05-06 16:27
My shocked face 😶
-
@northernlights@lemmy.today 2026-05-06 22:39
I wouldn’t have expected any less.
-
@auntieclokwise@lemmy.world 2026-05-07 04:19
And it gets even stranger. Apparently, the app is loading JavaScript from a random person’s GitHub site for YouTube embeds. Yes, you read that right, it’s just loading JavaScript from a random GitHub site. So if that account ever gets compromised, arbitrary code could run inside the app’s WebView. Somebody has the opportunity to do the most hilarious thing.
-
@twoBrokenThumbs@lemmy.world 2026-05-07 02:57
At least they acknowledge that cookie consent does nothing and paywalls are ridiculous.