Skip to content

COVIDSafe on Android up to v1.0.16 allowed a device to be re-identified over long periods of time due to static random data in the BLE payload

High
covidsafe-support published GHSA-8782-q64h-7rv3 Jul 23, 2020

Package

No package listed

Affected versions

<1.0.17

Patched versions

1.0.17

Description

Impact

Due to how the COVIDSafe app was generating random data in the BLE advertising payload, it was possible for an attacker to re-identify a device from previous encounters over long periods of time. This was caused by the fact the random data generated by the Android COVIDSafe app for the BLE advertising payload was generated on app startup and used for the life of the running app.

Patches

This issue was fixed in COVIDSafe v1.0.17 for Android.

References

https://nvd.nist.gov/vuln/detail/CVE-2020-12858

Severity

High

CVE ID

CVE-2020-12858

Weaknesses

No CWEs

Credits