PayRange Response to Android App Vulnerability Report
Published: August 28, 2026
Overview: This statement responds to security research recently published regarding the PayRange Android app.
Security is a top priority at PayRange. We recently became aware of a published report regarding vulnerabilities in the PayRange Android application, and we appreciate the time and effort the researcher put into identifying and reporting these issues.
We have completed an initial investigation, addressed the reported vulnerabilities, and want to provide our customers, partners, employees, and users with additional context about what was reported, what we have learned, and the actions we have taken.
A Vulnerability Is Not the Same as a Compromise
First, it is important to distinguish between a vulnerability and a compromise.
A vulnerability is a weakness that could potentially be exploited. A compromise occurs when someone actually exploits that weakness to gain unauthorized access to a system, account, or information.
An easy analogy is an unlocked door. An unlocked door is a vulnerability. Someone discovering the unlocked door and entering the home without permission is a compromise. The existence of the unlocked door does not, by itself, mean anyone entered the home.
The recently published report identified vulnerabilities in the PayRange Android application. They did not report an actual compromise.
We have investigated the reported vulnerabilities and the potential impact. Based on our investigation and the evidence available to us, we do not believe these vulnerabilities resulted in a compromise of the PayRange Android app.
We nevertheless take the vulnerabilities seriously. A security weakness should be addressed whether or not it was ever exploited, and that is what we have done.
Android Application Vulnerabilities
The researcher identified two vulnerabilities in the PayRange Android application involving SSL certificate validation and JavaScript functionality within certain application WebViews. These vulnerabilities have been assigned CVE-2026-13461 and CVE-2026-13462.
The reported SSL vulnerability could potentially allow an attacker on the same local network as an Android user to intercept communications between the user’s device and the internet to interfere with certain communications within the application. This type of attack is commonly referred to as an “on-path” or “man-in-the-middle” attack.
Importantly, the identification of this vulnerability does not mean such an attack actually occurred.
PayRange released Android application version 7.1.0 on August 27, 2026, which includes remediation for the reported vulnerabilities. We strongly recommend that all Android users update to the latest version of the PayRange Android application.
This vulnerability does not impact payment sent to BluKey devices as those commands are encrypted by PayRange servers and are not generated or processed by the application itself.
Reference to an Unrelated Website
The researcher also identified an unusual reference to fetlifestatus.com within certificate-validation logic in the Android application and suggested that its presence could indicate malware or a deliberately created “backdoor.”
We understand why the presence of an unrelated domain would raise questions. It raised questions for us as well.
Our investigation has determined that the domain was knowingly added to the validation logic in the past and was not inserted through malware. Our current investigation indicates that its inclusion was associated with historical certificate-validation logic. We are continuing to review the history surrounding why that particular domain was included.
Most importantly, we have found no evidence that the domain was included to create a backdoor or provide unauthorized access to PayRange systems.
The underlying certificate-validation vulnerability existed independently of this particular domain or any of the other domains referenced in the validation logic.
The unrelated domain was removed from the application on August 1, 2026, as part of a separate update and is no longer included.
Payment Card Information and PCI Compliance
The published report also raised concerns about the potential exposure of payment card information and stated that PayRange has not been PCI compliant since 2021.
We do not agree with that characterization.
PayRange takes the protection of payment information extremely seriously and has undergone PCI certification annually. PayRange has been certified as PCI-compliant every year.
PCI certification does not mean that a company can never have a security vulnerability. Security vulnerabilities can and do occur in technology systems, including those operated by PCI-compliant companies. What matters is how vulnerabilities are identified, investigated, and remediated as part of an organization’s ongoing security practices, which is what we’ve done in response to this discovery.
Attempts to Report the Vulnerabilities to PayRange
The researcher also stated that multiple attempts were made to notify PayRange of these vulnerabilities and that those attempts did not receive an appropriate response.
On this point, we acknowledge that our process did not work as it should have.
PayRange has a Security Response Team and a dedicated email address for vulnerability disclosures. After learning that the researcher’s reports had not reached the appropriate people, we reviewed our communication systems and processes to understand what happened.
Our review found an unusual but important circumstance.
Due to a misconfiguration of our email client when handling encrypted messages, the original email sent to our security team, as well as subsequent emails, contained no message in the body of the email explaining that the sender was a security researcher or that the attachment contained a vulnerability report. The details only appeared to be provided in an unsolicited attachment.

As a matter of security practice, our employees are trained to be extremely cautious about opening unsolicited attachments, particularly when an email contains no accompanying explanation. In this case, the messages appeared suspicious and were believed to potentially be phishing or malicious emails. The attachments were therefore not opened.
That explains how the initial report was missed. It does not change the fact that a legitimate security report did not reach the people who needed to see it.
The researcher also reported sending an email to PayRange Customer Support regarding the vulnerability. As part of our investigation, we searched our support system but were unable to locate the ticket or determine what happened to it. Regardless, a report of a potential security vulnerability received by our Customer Support team should be escalated to our Security Response Team.
The researcher also reported attempting to reach PayRange through regular mail and fax. We have not located the referenced letter and continue to review what may have occurred. Fax is not monitored by the PayRange Security Response Team.
We recognize that, taken together, these attempts exposed opportunities to improve how potential security reports are identified and routed within our organization. We are reinforcing our escalation procedures, retraining appropriate personnel, and implementing additional safeguards. We will clarify the vulnerability disclosure process on our website so security researchers know how to reach the appropriate team.
We want security researchers to be able to reach us, and we will make that process better.
Open-Source Software Notices
The researcher separately identified missing copyright notices associated with certain third-party open-source software used in the Android application.
Our review confirmed that certain required copyright notices had not been included. We are correcting those omissions.
The researcher also raised a GPLv3 licensing issue associated with AVR-Crypto-Lib. The newly released PayRange Android application, version 7.1.0, no longer uses the AVR-Crypto-Lib library.
What We Have Done
As part of our response, PayRange has:
- Released Android application version 7.1.0 addressing the reported Android vulnerabilities.
- Removed the unrelated domain identified in the historical certificate-validation logic.
- Reviewed the security implications of the reported vulnerabilities and investigated for evidence of compromise.
- Reviewed our vulnerability-reporting and escalation processes.
- Begun additional training and process improvements for handling security-related communications.
- Implemented additional routing and escalation safeguards for potential security reports.
- Addressed the identified open-source licensing and attribution issues.
- We will continue reviewing our systems and processes for additional improvements.
Moving Forward
Security is an ongoing responsibility. No technology company can credibly promise that a vulnerability will never be discovered. What we can commit to is taking vulnerabilities seriously, investigating them carefully, addressing them promptly, and learning from them.
The vulnerabilities reported here deserved our attention, and we appreciate the researcher’s work in identifying them.
We encourage security researchers to continue bringing potential vulnerabilities to our attention. We have an active Bug Bounty program with which we routinely make payments for verified vulnerabilities. Information about reporting security concerns and vulnerabilities is available at payrange.com/security.
PayRange Security Response Team

