Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Joel Reardon

Researcher fromAppCensus
#52946of 53,633
3.3Total CVSS
Vulnerabilities · 1
PT-2021-19522
3.3
2021-04-28
Google/Apple · Gaen · CVE-2021-31815
**Name of the Vulnerable Software and Affected Versions** GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android **Description** The issue allows attackers to obtain sensitive information, such as a user's location history, in-person social graph, and sometimes COVID-19 infection status. This is because Rolling Proximity Identifiers and MAC addresses are written to the Android system log. Many Android devices have applications that read system log data and send it to third parties. **Recommendations** For GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android, wait for the fix deployment to be complete, as the vendor has indicated that the deployment began several weeks ago and will be finished in the coming days.