Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges.
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 30 Dec 2024 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges. After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices. | |
Title | Location information exposure in Infinix Weather app | |
Weaknesses | CWE-497 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2024-12-30T14:14:56.228Z
Reserved: 2024-12-27T14:13:53.615Z
Link: CVE-2024-12993

Updated: 2024-12-30T14:14:52.332Z

Status : Received
Published: 2024-12-30T11:15:06.100
Modified: 2024-12-30T11:15:06.100
Link: CVE-2024-12993

No data.