Description
Skype for Android stores sensitive user data without encryption in sqlite3 databases that have weak permissions, which allows local applications to read user IDs, contacts, phone numbers, date of birth, instant message logs, and other private information.
References (4)
Core 4
Core References
Exploit x_refsource_misc
http://www.androidpolice.com/2011/04/14/exclusive-vulnerability-in-skype-for-android-is-exposing-your-name-phone-number-chat-logs-and-a-lot-more/
Various Sources x_refsource_confirm
http://blogs.skype.com/security/2011/04/privacy_vulnerability_in_skype.html
Various Sources x_refsource_misc
http://www.theregister.co.uk/2011/04/15/skype_for_android_vulnerable/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1025387
Scores
EPSS
0.0029
EPSS Percentile
21.5%
Details
CWE
CWE-264
Status
published
Products (1)
skype/skype_for_android
Published
Apr 18, 2011
Tracked Since
Feb 18, 2026