Incorrect Privilege Assignment
CVE-2020-24653
Summary
Secure-store in Expo through 9.0.1 on iOS provides the insecure "kSecAttrAccessibleAlwaysThisDeviceOnly" policy when "WHEN_UNLOCKED_THIS_DEVICE_ONLY" is used.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-266 - Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
References
Advisory Timeline
- Published