Health maintains a small but notable vulnerability footprint across consumer and public-health applications, most notably in contact-tracing and informational tools such as CovidSafe and related products. The disclosed vulnerabilities skew toward serious outcomes, with a meaningful share reaching critical severity, and center on structural weaknesses including cleartext storage of sensitive information, improper privilege management, incomplete cleanup, and use of insufficiently random values—issues endemic to applications handling personal or health data. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Health over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12856CRITICAL OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identifi | May 18, 2020 | 9.8 | 27 | NO | NO |
CVE-2020-12858HIGH Non-reinitialisation of random data in the advertising payload in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to re-identify Android devices running COVIDSafe by scannin | May 18, 2020 | 7.5 | 20 | NO | NO |
CVE-2020-12860MEDIUM COVIDSafe through v1.0.17 allows a remote attacker to access phone name and model information because a BLE device can have four roles and COVIDSafe uses all of them. This allows f | May 18, 2020 | 5.3 | 19 | NO | NO |
CVE-2020-12859MEDIUM Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This all | May 18, 2020 | 5.3 | 19 | NO | NO |
CVE-2020-12857HIGH Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe. | May 18, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-12717MEDIUM The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement | May 14, 2020 | 6.5 | 18 | NO | NO |
CVE-2020-14292MEDIUM In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establis | Sep 9, 2020 | 5.7 | 16 | NO | NO |
CVE-2014-7360MEDIUM The How To Boil Eggs (aka com.appmakr.app842173) application 251333 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spo | Oct 19, 2014 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Health.
Media articles that mention a CVE ID that affects a product developed by Health — matched by CVE ID, not by vendor name.