CVE-2020-24722 describes a medium-severity vulnerability in the Google/Apple Exposure Notifications (GAEN) protocol, used in COVID-19 contact tracing applications on Android and iOS. The flaw stems from the absence of a checksum in the encrypted metadata block, enabling bitflipping attacks. This can lead to metadata deanonymization and inflated risk scores, though the vendor believes TX power authentication wouldn't effectively counter relay attacks. With a CVSS score of 5.9, this vulnerability has a network attack vector and high attack complexity, but does not require user interaction or privileges. The primary impact is a high integrity loss, with no confidentiality or availability impact. Currently, there is no evidence of active exploitation, and no public exploit code exists on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2020-10-05CPE matchmatch criteria | cpe:2.3:a:exposure_notifications_project:exposure_notifications:*:*:*:*:*:android:*:* | ||
<= 2020-10-05CPE matchmatch criteria | cpe:2.3:a:exposure_notifications_project:exposure_notifications:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.