EU’s New Age Verification App Vulnerable to Hacking, Chirag Goswami Reports

C

Chirag Goswami

LinkedIn Author

Founder @ Cybernara | Security-First Managed IT & Cloud Partner | Cloud, M365 & GRC | LinkedIn Top Voice

In a recent LinkedIn post, Chirag Goswami discusses significant security vulnerabilities discovered in the European Union’s new age verification app, launched on April 16, 2026. Goswami highlights how the app, designed to allow users to prove they are over 18 online without revealing extensive personal data, was reportedly compromised in under two minutes by security researchers.

Security Flaws in EU Age Verification App

The EU’s initiative aimed to provide a privacy-preserving method for age verification. Users were intended to first authenticate with the app using official identification. Subsequently, when visiting a website requiring age confirmation, the app would only signal whether the user met the age requirement, rather than sharing sensitive details like names or ID numbers. Goswami explains the intended functionality:

The idea was simple: users would first verify themselves through the app using an official identity source such as a government ID or digital identity record. After that, when visiting a website, the app would only confirm whether the person is above the required age instead of sharing name, ID number, or other private data.

However, Goswami reports that security researchers quickly identified critical flaws. These issues reportedly included the local storage of PIN-related data on the device and the possibility of altering security settings within app files. According to Goswami, these vulnerabilities could allow attackers to reset protections, bypass login attempt limits, and disable biometric security measures.

Implications of Weak App Security

Chirag Goswami emphasizes the broader implications of such security weaknesses. If an age-verification system is easily bypassed, it can lead to unauthorized access, misuse of online services, and a general erosion of public trust in digital privacy solutions. Goswami points out the potential consequences:

If an age-check app is weak, people may fake access, misuse accounts, or lose trust in systems meant to protect privacy.

This situation serves as a critical lesson for companies developing digital products and services, particularly those handling sensitive user data or implementing privacy-focused features. Goswami argues that the effectiveness of privacy measures is directly contingent on the underlying security infrastructure.

Integrating Cybersecurity from the Outset

A key takeaway highlighted by Goswami is the imperative to embed cybersecurity into the product development lifecycle from the very beginning. Simply adding security features as an afterthought is insufficient and can inadvertently create new risks.

The Danger of Good Intentions with Weak Design

Goswami’s analysis underscores a fundamental principle in cybersecurity: a well-intentioned design can become a significant liability if its security architecture is weak. He states:

Good intention + weak design = new risk.

Therefore, Goswami strongly advocates for a proactive approach, asserting that cybersecurity must be an integral part of the product from day one. This includes rigorous testing, threat modeling, and secure coding practices to ensure that privacy-enhancing technologies are also robust and resilient against exploitation. The incident with the EU app, as reported by Goswami, serves as a stark reminder of this necessity in the digital age.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on April 18, 2026 | View original post on LinkedIn →