Substack
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
Substack is a new media app that connects you with the creators, ideas, and communities you care about most. - Support the creators you love: Subscribe for free or upgrade to view original work and connect directly with your favorite writers, artists, and podcasters. - Enjoy ad-free videos and podcasts: Access short-form clips, video episodes, and read-aloud articles without interruptions. - Connect in real time: Join livestreams and live group chats, where top creators bring their biggest supporters into their world. - Explore independent ideas: Discover bold opinions and engaging views across food, sports, politics, fashion, comedy, finance, and more. How it works: 1. Download the Substack app. 2. Claim your handle. 3. Explore the feed to enjoy notes, videos, and clips from creators. 4. Subscribe to your favorites for free, tune into their livestreams and join private group chats.
Data collected and shared
Source: App Store · App Privacy · 6 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
Other apps by this publisher
Apps published by Substack Inc.
FAQ
FAQ: Substack
Why are no CVEs listed for Substack?
No CVE is currently referenced in NVD for Substack (com.substack.Substack) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of Substack?
The most recent version of Substack (com.substack.Substack) tracked by Appaloosa Scout is 3.9.0, published by Substack Inc..