VYPR
Unrated severityNVD Advisory· Published Aug 21, 2023· Updated Jul 2, 2025

Butterfly Button Project - Sensitive Information Disclosure

CVE-2023-40735

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) allows loss of plausible deniability and confidentiality.This issue affects BUTTERFLY BUTTON: As of 2023-08-21.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The BUTTERFLY BUTTON SDK leaks sensitive user activity to the hosting app, breaking promised anonymity for domestic-violence help-seekers.

Vulnerability

The BUTTERFLY BUTTON SDK, designed to provide anonymous domestic-violence assistance via a website or app button, contains an architecture flaw that exposes sensitive information to the hosting application. The SDK fails to isolate user interactions (click events, session data, or the fact that help was sought) from the app’s own code, breaking the claimed plausible deniability. The affected SDK is the version analyzed as of 2023-08-21; no specific version number was disclosed [1][2][4].

Exploitation

An attacker who controls or has administrative access to the hosting website or application (or who can inject malicious code into the page) can monitor the SDK’s internal events or storage. No special network position is required if the attacker already has code execution in the app context. The exploitation requires only that the attacker’s code is present alongside the SDK’s code [3][4].

Impact

A successful attack reveals that a user has used the BUTTERFLY BUTTON, destroying the promised confidentiality and plausible deniability. In a domestic-violence context, this loss of anonymity could put the user at immediate physical risk. The impact is a direct information disclosure of a victim’s help-seeking behavior [2][3].

Mitigation

No fixed version has been announced as of 2023-08-21. Developers integrating the SDK are advised to review the SDK’s architecture and, if possible, sandbox the SDK in an iframe or separate process to prevent data leakage to the host application. The vendor’s GitHub repository and website did not provide a security update [1][4].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.