Description
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-12731 | Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated. |
References
| Link | Providers |
|---|---|
| https://www.whatsapp.com/security/advisories/2020/ |
|
History
No history.
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2024-08-04T06:53:59.620Z
Reserved: 2019-12-02T00:00:00.000Z
Link: CVE-2020-1905
No data.
Status : Modified
Published: 2020-10-06T18:15:16.580
Modified: 2024-11-21T05:11:35.110
Link: CVE-2020-1905
No data.
OpenCVE Enrichment
No data.
EUVD