Investigation

Healthcare Chatbot Security Investigation

An investigation of a real healthcare chatbot that shipped credentials in its frontend.

Finding#

The vulnerability was rated CVSS 10.0. The central issue was not merely that a secret was visible in the frontend. The trust boundary had been drawn in the wrong place: information that could not be protected there was included in the delivered application.

Why it mattered#

Frontend code and the data shipped with it run on the user’s side. Placing credentials there treats that environment as a protected boundary even though it is not one.

Disclosure and verification#

I investigated the real system and reported the finding responsibly. After the later fix, I checked the system again to verify that the vulnerability had actually been resolved.

Outcome#

The remediation was verified. Further exploit details, credential values, and assumptions about the backend architecture are intentionally not documented here.