CVE ID | CVE-2024-12993 |
Publication date | 30 December 2024 |
Vendor | Infinix Mobile |
Product | com.rlk.weathers |
Vulnerable versions | 7.0.0.037 |
Vulnerability type (CWE) | Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Infinix Mobile com.rlk.weathers
software and participated in coordination of its disclosure.
Infinix devices contain a preloaded com.rlk.weathers
application vulnerable to CVE-2024-12993, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges.
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
Credits
We thank Szymon Chadam for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.