Advertisement


Looking for a fix? Check your Codebase security with multiple scanners from Scanmycode.today


Edit Report

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020020095

Below is a copy:

Global TV Unencrypted Analytics
Global TV Android & iOS Applications - Unencrypted Analytics (CVE-2020-8506)
--
https://www.info-sec.ca/advisories/Global-TV.html

Overview

"Watch the latest full episodes of your favourite Global shows"

(https://play.google.com/store/apps/details?id=com.shawmedia.smglobal)
(https://apps.apple.com/ca/app/global-tv/id404050595)

Issue

The Global TV Android & iOS applications (Android version 2.3.2 and below, iOS version 4.7.5 and below) sends potentially sensitive information such as device model & resolution, mobile carrier, days since first use, days since last use, total number of app launches, number of app launches since upgrade, and previous app session length, unencrypted to both first (CNAME to third) and third party sites (Adobe Experience Cloud, ScorecardResearch).

Impact

An attacker who can monitor network traffic could capture potentially sensitive information about the user's device and viewing habits without their knowledge.

Timeline

October 7, 2019 - Provided additional information about my research on unencrypted analytics to Apple via [email protected]
October 17, 2019 - Attempted to obtain a security contact via a Global TV support form
October 22, 2019 - Provided the details to the Adobe PSIRT via [email protected] and asked for assistance contacting the vendor
November 14, 2019 - Attempted to obtain a security contact via an email to [email protected]

Solution

The Global TV Android & iOS applications as of February 4, 2020 are affected.

CVE-ID:

CVE-2020-8506

Copyright ©2020 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.