PT-2025-4301 · Aat · Aat

Ntc-Swiss-Team

·

Published

2025-01-06

·

Updated

2025-01-06

·

CVE-2025-21615

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AAT (Another Activity Tracker) versions prior to 1.26
Description AAT is a GPS-tracking application for tracking sportive activities, with an emphasis on cycling. The issue allows for data exfiltration from malicious apps installed on the same device.
Recommendations For versions prior to 1.26, update to version 1.26 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data within the application to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-21615
GHSA-PWPM-X58V-PX5C

Affected Products

Aat