Investigation
Healthcare Chatbot Security Investigation
An investigation of a real healthcare chatbot that shipped credentials in its frontend.
Finding#
The vulnerability was rated CVSS 10.0. The central issue was not merely that a secret was visible in the frontend. The trust boundary had been drawn in the wrong place: information that could not be protected there was included in the delivered application.
Why it mattered#
Frontend code and the data shipped with it run on the user’s side. Placing credentials there treats that environment as a protected boundary even though it is not one.
Disclosure and verification#
I investigated the real system and reported the finding responsibly. After the later fix, I checked the system again to verify that the vulnerability had actually been resolved.
Outcome#
The remediation was verified. Further exploit details, credential values, and assumptions about the backend architecture are intentionally not documented here.