MEGA
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +6/+10
1 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
MEGA is one app for everything private. Securely store, back up, share files, and chat, protected by true zero-knowledge encryption. Only you can access your files. Not even us. Store & back up - 20 GB of free encrypted cloud storage, no credit card required - Automatic camera backup for your photos and videos - Access your files from any device, anywhere, anytime - Restore previous versions with file version history Share & collaborate - Share files and folders with secure, password-protected links - Set expiry dates on shared links for time-limited access - Collaborate in real time with folder sharing - Transfer large files to anyone, no MEGA account needed Chat & meet privately - End-to-end encrypted one-on-one and group chats - Encrypted audio and video calls - Chat history synced automatically across all your devices Privacy by design - Zero-knowledge encryption, your data is encrypted and decrypted on your device only - MEGA cannot read your files, messages, or calls - Open-source code, publicly available and independently audited on GitHub - Your account recovery key ensures only you can access your data Start free with 20 GB of private cloud storage.
Data collected and shared
Source: App Store · App Privacy · 10 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: MEGA
Why are no CVEs listed for MEGA?
No CVE is currently referenced in NVD for MEGA (mega.ios) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of MEGA?
The most recent version of MEGA (mega.ios) tracked by Appaloosa Scout is 18.10.1, published by Mega Limited.