Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Cjthompson

#25700of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2020-15794
9.8
2020-08-26
Expo · Expo · CVE-2020-24653
**Name of the Vulnerable Software and Affected Versions** Expo versions through 9.1.0 on iOS **Description** The issue concerns the `secure-store` in Expo, which provides an insecure policy `kSecAttrAccessibleAlwaysThisDeviceOnly` when `WHEN UNLOCKED THIS DEVICE ONLY` is used. This affects the security of data storage on iOS devices. **Recommendations** For Expo versions through 9.1.0 on iOS, consider updating to a version that addresses this issue, as the current version provides an insecure policy that may compromise data security. At the moment, there is no information about a newer version that contains a fix for this vulnerability.