TraceTogether is a contact-tracing application developed to support public health surveillance during disease outbreaks, representing a narrowly scoped product with limited vulnerability surface area. The observed disclosures cluster around insufficient information classifications, reflecting the challenges in detailed characterization of flaws in health-surveillance tools; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tracetogether over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12856CRITICAL OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identifi | May 18, 2020 | 9.8 | 27 | NO | NO |
CVE-2020-12717MEDIUM The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement | May 14, 2020 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tracetogether.
Media articles that mention a CVE ID that affects a product developed by Tracetogether — matched by CVE ID, not by vendor name.