Nothing Chat catastrophe — more vulnerabilities discovered in iMessage clone

Nothing Phone (2) review.
(Image credit: Future)

The recent launch of Nothing's new messaging app, Nothing Chats, designed to bring a version of Apple’s iMessage to Android, went down like a lead balloon. Just one day after going live on the Google Play Store, Nothing pulled the app over serious security concerns. Now, two more vulnerabilities have purportedly come to light. 

As spotted by Android Authority, Android developer and reverse engineer Dylan Roussel, who previously blew the whistle on security issues with Nothing Chats and the Sunbird platform it's built on, recently shared on X two additional vulnerabilities centered around Nothing's infrastructure. 

The first dates back to September and was discovered in the CMF Watch app, which was reportedly developed in partnership with Nothing and a company called Jingxun. According to Roussel, while the app successfully encrypted both email and password information, the encryption method it used wasn't secure. Anyone with access to the same decryption keys would have all the tools to decrypt the information, which kind of defeats the purpose of encrypting it to begin with. 

Roussel said Nothing/Jingxun has since addressed this vulnerability, but the fix apparently only works for passwords. You could still allegedly decrypt the email address that is used as someone's username. 

As for the second vulnerability, exact details haven't been publicly released, but it purportedly relates to Nothing's internal data. The company was informed of it in August, and the issue remains unpatched.

In a statement to Android Authority, a Nothing spokesperson said the company is currently working to resolve the issues:

"CMF takes privacy issues very seriously and the team is investigating security concerns regarding the Watch app. We rectified initial credential concerns earlier in the year and are currently working to resolve the issues raised. As soon as this next fix is complete, we will roll out an OTA update to all CMF Watch Pro users."

The rep added that security reports are now easier to submit on CMF's security vulnerability report page.

Roussel previously blew the lid on how Sunbird, the platform Nothing Chats is built on, works by decrypting and transmitting messages via HTTP to a Firebase cloud-syncing server and storing them in unencrypted plain text. Thus, Sunbird messages are publicly visible via the Firebase real time database, and not encrypted. He also noted that Sunbird also has access to these messages, since they’re logged as errors by debugging service Sentry.

The official Nothing Chats page confirms that the beta app has been pulled from the Play Store, and the company now says it will be "delaying the launch until further notice" pending the fix of “several bugs."

One of the biggest selling points of iMessage is that it offers end-to-end encryption by default. Apple has cited additional security as one of the reasons why it will be adopting the RCS messaging standard next year. In both cases your messages are secure, and inaccessible by third parties — Apple included. Instead, Nothing promised end-to-end encryption, only to then store texts publicly in plaintext. It's quite the fumble — and whether it's one Nothing can recover from remains to be seen.  

More from Tom's Guide

TOPICS
Alyse Stanley
News Editor

Alyse Stanley is a news editor at Tom’s Guide, overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment. Before Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher. She previously led Gizmodo’s weekend news desk and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. She’s a big fan of horror movies, cartoons, and roller skating.

Read more
How to tell if you've been blocked on WhatsApp
The best WhatsApp alternatives in 2025
An illustration of a person holding a smartphone with a padlock in front of speech bubbles on the screen
The best encrypted messaging apps in 2025
DeepSeek logo on smartphone in front of merging US and Chinese flags
DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about
RCS messaging on an iPhone
Forget green bubbles — iPhones will soon get encrypted RCS messaging to Androids
DeepSeek logo on mobile phone
Is DeepSeek safe to use?
One phone with skull and crossbones on screen among several other clean-looking phones.
Malicious iPhone apps are spreading screenshot-reading malware on the Apple App Store — how to stay safe
Latest in Phones
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Google Pixel 9 with Amazon Spring Sale deal tag
The Google Pixel 9 is at its lowest price ever for Amazon Spring Sale — 30% off now
Amazon Spring Sale Galaxy S25
Amazon’s Spring Sale drops the Samsung Galaxy S25 to $734 — its lowest price ever!
OnePlus 13 back, leaning against blue wall
OnePlus 13T could come with an even bigger battery than OnePlus 13 — this is incredible
Apple maps logo on iPhone screen
I avoided Apple Maps for trip planning — but these iOS 18 features are changing my mind
Latest in News
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know