Vulnerability Description
secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Expo | Expo | <= 2.16.1 |
References
- https://github.com/expo/expo/pull/9264PatchThird Party Advisory
- https://github.com/expo/expo/pull/9264PatchThird Party Advisory
FAQ
What is CVE-2020-24653?
CVE-2020-24653 is a vulnerability with a CVSS score of 9.8 (CRITICAL). secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
How severe is CVE-2020-24653?
CVE-2020-24653 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-24653?
Check the references section above for vendor advisories and patch information. Affected products include: Expo Expo.