CVE-2020-13702 describes a critical privacy bypass vulnerability in the Apple/Google Exposure Notification API beta's Rolling Proximity Identifier, affecting the_rolling_proximity_identifier_project. An attacker can leverage a secondary temporary UID to circumvent Bluetooth Smart Privacy, enabling seamless tracking of individual device movement via Bluetooth LE discovery. With a CVSS score of 10.0 (Critical), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality and integrity. While no active exploits, public exploit code, or significant community discussion have been observed, its high FAUCET Risk Score of 81/100 indicates a significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2020-05-29CPE matchmatch criteria | cpe:2.3:a:the_rolling_proximity_identifier_project:the_rolling_proximity_identifier:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.