Unsecured Content Provider in Infinix Mobile Devices
CVE-2024-12993
4.8MEDIUM
What is CVE-2024-12993?
Infinix mobile devices are impacted by a serious security issue involving the pre-installed 'com.rlk.weathers' application. This application features an unsecured content provider that can be accessed by attackers. With this vulnerability, an attacker is capable of communicating with the content provider, which may allow them to reveal sensitive information, such as the user's location. Despite multiple attempts to reach out to Infinix for clarification or a patch, no response has been received, raising concerns that this flaw could affect all models in the Infinix mobile device line.
Affected Version(s)
com.rlk.weathers Android 7.0.0.037