PT-2020-13655 · Google/Apple · Apple/Google Exposure Notification Api

Published

2020-06-11

·

Updated

2021-03-12

·

CVE-2020-13702

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apple/Google Exposure Notification API beta through 2020-05-29
Description The issue enables attackers to circumvent Bluetooth Smart Privacy due to a secondary temporary UID in the Rolling Proximity Identifier. This allows an attacker with access to Beacon or IoT networks to track individual device movement via a Bluetooth LE discovery mechanism.
Recommendations For Apple/Google Exposure Notification API beta through 2020-05-29, consider disabling the Rolling Proximity Identifier until a patch is available to prevent exploitation. Restrict access to Beacon or IoT networks to minimize the risk of tracking individual device movement.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13702

Affected Products

Apple/Google Exposure Notification Api