Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://github.com/mame82/misc/blob/master/luca_traceIds.md | third party advisory |
https://luca-app.de/securityoverview/properties/objectives.html | vendor advisory |
https://www.youtube.com/playlist?list=PLKuX6iczGb3kuDsm2RFgbmRkTugkR9-UE | third party advisory exploit |
https://www.ccc.de/de/updates/2021/luca-app-ccc-fordert-bundesnotbremse | third party advisory |