Impact
The vulnerability arises from the updater’s design, in which a private key is distributed can be derived from the private key, an attacker who performs a man‑in‑the‑middle attack on the update channel or compromises the Capgo server can forge a signed update bundle that the device will accept as legitimate. Installing such a malicious update would allow the attacker to execute arbitrary code on the device, compromising confidentiality, integrity, and availability of the application and its underlying system.
Affected Systems
Capgo capacitor-updater (Cap-go/capgo) versions prior to 12.128.2 are affected by the key distribution flaw in the updater module.
Risk and Exploitability
The CVSS score of 8.3 signals a high severity risk, while the EPSS score of <1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a man‑in‑the‑middle interception of the update channel or the Capgo server, both of which enable the attacker to create and serve a validly signed malicious update bundle.
OpenCVE Enrichment