Leap maintains a narrow portfolio of privacy and security-focused applications including a blue-light filter and a Bitmask/Riseup VPN client, with a modest vulnerability footprint centered on authorization, permission assignment, and sensitive data storage. The observed weakness classes reflect the access-control and credential-handling demands of these end-user security tools; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leap over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44466HIGH Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off o | Dec 30, 2021 | 7.3 | 24 | NO | NO |
CVE-2023-29757HIGH An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files. | Jun 9, 2023 | 7.8 | 21 | NO | NO |
CVE-2023-29758MEDIUM An issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files. | Jun 9, 2023 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leap.
Media articles that mention a CVE ID that affects a product developed by Leap — matched by CVE ID, not by vendor name.