CVE-2020-13626: Medium severity oneplus app locker vulnerability
OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13626?
CVE-2020-13626 is considered to be a high severity vulnerability due to its potential for unauthorized SMS access.
How do I fix CVE-2020-13626?
To mitigate CVE-2020-13626, update the OnePlus App Locker to a version released after October 6, 2020.
What does CVE-2020-13626 allow an attacker to do?
CVE-2020-13626 allows a physically proximate attacker to use Google Assistant to bypass the App Locker and send SMS messages.
Is CVE-2020-13626 specific to certain OnePlus devices?
CVE-2020-13626 affects OnePlus devices that utilize the App Locker feature with versions up to and including 2020-10-06.
What are the implications of CVE-2020-13626 for user privacy?
CVE-2020-13626 poses a risk to user privacy as it allows unauthorized SMS sending, which can lead to exploitation of personal information.