| |
Vulnerability CVE-2018-19111
Published: 2018-11-08
Description: |
The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS. |
Type:
CWE-319 (Cleartext Transmission of Sensitive Information)
CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5/10 |
2.9/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
None |
None |
References: |
https://www.info-sec.ca/advisories/Google-Cardboard.html
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|