PT-2020-13623 · Google+1 · Google Assistant+1
Published
2020-10-09
·
Updated
2020-10-20
·
CVE-2020-13626
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OnePlus App Locker versions prior to 2020-10-06
Description
The issue allows physically proximate attackers to bypass an authorization check using Google Assistant. This can lead to sending an SMS message when the SMS application is locked.
Recommendations
For versions prior to 2020-10-06, consider disabling the Google Assistant integration with the App Locker as a temporary workaround until a patch is available. Restrict access to the locked SMS application to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Assistant
Oneplus App Locker