Skip to content

COVIDSafe on Android up to v1.0.16 allowed a device to be re-identified over long periods of time due to a tempID caching issue

High
covidsafe-support published GHSA-q76c-hmq5-h7q7 Jul 23, 2020

Package

No package listed

Affected versions

<1.0.17

Patched versions

1.0.17

Description

Impact

Due to how the COVIDSafe app was handling the caching of tempIDs, it was possible for an attacker to query this cache over an extended period of time, returning the cached tempID rather than a refreshed tempID. This would allow the attacker to re-identify a device from a previous encounter, which can be used for long term tracking of a device beyond the intended lifespan of a tempID.

Patches

This issue was fixed in COVIDSafe v1.0.17 for Android.

References

https://nvd.nist.gov/vuln/detail/CVE-2020-12857

Severity

High

CVE ID

CVE-2020-12857

Weaknesses

No CWEs

Credits