CVE-2020-12856

CRITICAL

OpenTrace <v1.0.17 - Info Disclosure

Title source: llm

Description

OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.

Exploits (1)

nomisec WORKING POC 25 stars
by alwentiu · poc
https://github.com/alwentiu/COVIDSafe-CVE-2020-12856

Scores

CVSS v3 9.8
EPSS 0.1076
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (4)
alberta/abtracetogether (2 CPE variants)
health/covidsafe
health/covidsafe < 1.0.17
tracetogether/tracetogether (2 CPE variants)
Published May 18, 2020
Tracked Since Feb 18, 2026