The Exposure Notifications Project maintains a focused framework for privacy-preserving exposure-alert systems, centered on its Exposure Notifications product that enables health authorities and applications to notify individuals of potential pathogen exposure without disclosing location or identity. The observed vulnerability signal centers on authentication-bypass mechanisms, particularly capture-replay attacks that could undermine the confidentiality model underlying the notification flow. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exposure Notifications Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24722MEDIUM An issue was discovered in the GAEN (aka Google/Apple Exposure Notifications) protocol through 2020-10-05, as used in COVID-19 applications on Android and iOS. The encrypted metada | Oct 7, 2020 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exposure Notifications Project.
Media articles that mention a CVE ID that affects a product developed by Exposure Notifications Project — matched by CVE ID, not by vendor name.