CVE-2020-12856

CRITICAL

OpenTrace <v1.0.17 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-12856. PoCs published by alwentiu.

AI-analyzed exploit summary This PoC demonstrates a silent pairing vulnerability in Bluetooth-based contact tracing apps (e.g., COVIDSafe v1.0.17 and earlier) by advertising a GATT server with an encrypted characteristic. When a vulnerable app connects and reads the characteristic, the phone bonds silently, exposing the IRK and other identifiers for long-term tracking.

Description

OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and possibly have unspecified other impact, because of how Bluetooth is used.

Exploits (1)

nomisec WORKING POC 25 stars
by alwentiu · poc
https://github.com/alwentiu/COVIDSafe-CVE-2020-12856

This PoC demonstrates a silent pairing vulnerability in Bluetooth-based contact tracing apps (e.g., COVIDSafe v1.0.17 and earlier) by advertising a GATT server with an encrypted characteristic. When a vulnerable app connects and reads the characteristic, the phone bonds silently, exposing the IRK and other identifiers for long-term tracking.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: COVIDSafe (Android) v1.0.17 and earlier, similar apps like TraceTogether and ABTraceTogether
No auth needed
Prerequisites: Bluetooth-enabled Linux system with BlueZ stack · Python-dbus package · Vulnerable app installed on target Android device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0514
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (4)
alberta/abtracetogether (2 CPE variants)
health/covidsafe
health/covidsafe < 1.0.17
tracetogether/tracetogether (2 CPE variants)
Published May 18, 2020
Tracked Since Feb 18, 2026