The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and disclose sensitive data such as user profile information and GPS coordinates, among others.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-05-23T00:00:00
Updated: 2024-08-02T10:28:40.605Z
Reserved: 2023-01-11T00:00:00
Link: CVE-2023-23299
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-05-23T20:15:09.330
Modified: 2024-11-21T07:45:57.840
Link: CVE-2023-23299
Redhat
No data.