Aarogyasetu_android: [Urgent] CVE-2020-12856

Created on 28 May 2020  路  3Comments  路  Source: nic-delhi/AarogyaSetu_Android

This CVE has been found in several other Bluetooth-based contact tracing apps (notably Australia's COVIDSafe, Singapore's OpenTrace, and Alberta's ABTraceTogether). We believe that Aarogya Setu may also be vulnerable.

It has been assigned a severity of 9.8 Critical. It primarily affects Android but should also be addressed on iPhone.

Some more information is available at https://github.com/alwentiu/COVIDSafe-CVE-2020-12856 however the full details are not currently public and are under embargo until June 19. However we have emailed [email protected] with the full details. Please contact us if you have any further questions.

CC @alwentiu

Most helpful comment

Confirming that you _really_ should speak with Jim. It's gonna look super bad on the 19th if you haven't engaged and worked on a mitigation.

https://docs.google.com/document/d/17sVyBIG5CqhF9XtuEfeG2MfYsFNXuV4yxp3BERDTJoI/edit?usp=drivesdk

All 3 comments

Confirming that you _really_ should speak with Jim. It's gonna look super bad on the 19th if you haven't engaged and worked on a mitigation.

https://docs.google.com/document/d/17sVyBIG5CqhF9XtuEfeG2MfYsFNXuV4yxp3BERDTJoI/edit?usp=drivesdk

@delhiamitk FYI

BUMP. Exploit being released on the 19th.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

skullcandy69 picture skullcandy69  路  4Comments

dtchanpura picture dtchanpura  路  3Comments

anivar picture anivar  路  3Comments

rejuls picture rejuls  路  5Comments

tachyons picture tachyons  路  3Comments