Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/mame82/misc/blob/master/luca_traceIds.md | third party advisory |
https://luca-app.de/securityoverview/properties/objectives.html | vendor advisory |
https://youtu.be/jWyDfEB0m08 | third party advisory exploit |
https://twitter.com/patrick_hennig/status/1387738281757061125 | third party advisory |