PT-2021-19522 · Google/Apple · Gaen
Joel Reardon
+1
·
Published
2021-04-28
·
Updated
2021-05-07
·
CVE-2021-31815
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android
Description
The issue allows attackers to obtain sensitive information, such as a user's location history, in-person social graph, and sometimes COVID-19 infection status. This is because Rolling Proximity Identifiers and MAC addresses are written to the Android system log. Many Android devices have applications that read system log data and send it to third parties.
Recommendations
For GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android, wait for the fix deployment to be complete, as the vendor has indicated that the deployment began several weeks ago and will be finished in the coming days.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gaen