CVE-2020-14292
Published
CVSS v3
5.7
MEDIUM
CVSS v2
2.9
LOW
Affected
2
PROJECTS
Description
In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection over Bluetooth BR/EDR transport, which reveals the public Bluetooth address of the victim's phone without authorisation, bypassing the Bluetooth address randomisation protection in the user's phone.