Advertisement






Texture Canada Unencrypted Third Party Analytics

CVE Category Price Severity
CVE-2019-8632 CWE-311 Unknown High
Author Risk Exploitation Type Date
Unknown High Remote 2019-05-11
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019050120

Below is a copy:

Texture Canada Unencrypted Third Party Analytics
Texture Canada Android & iOS Applications - Unencrypted Third Party 
Analytics (CVE-2019-8632)
--
https://www.info-sec.ca/advisories/Texture.html

Overview

"Texture: Unlimited access to over 100 of the world's best magazines on 
your computer, smartphone or tablet."

(https://play.google.com/store/apps/details?id=com.nim.rogers)
(https://itunes.apple.com/ca/app/texture-canada/id649174756)

Issue

The Texture Canada Android & iOS applications (Android version 4.21.0.1, 
iOS version 5.11.6 and below) sends potentially sensitive information 
such as number of app launches, device model, Android or iOS version and 
screen resolution, unencrypted to a third party site (ScorecardResearch).

Impact

An attacker who can monitor network traffic could capture potentially 
sensitive information about the user's device without their knowledge.

Timeline

July 10, 2018 - Attempted to notify Texture of the issue via 
[email protected]
July 10, 2018 - Attempted to notify Texture of the issue via 
[email protected]
July 12, 2018 - Provided the details of the issue to Apple via 
[email protected]
May 9, 2019 - Published an advisory to document the issue

Solution

Upgrade to Android version 4.22.0.4 or iOS version 5.11.10 (U.S. 
versions are also affected but have not been tested)

https://support.apple.com/en-us/HT210110
https://support.apple.com/en-us/HT210111
https://support.apple.com/en-us/HT201222

CVE-ID:

CVE-2019-8632

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum