CVE-2024-3108CWE-927

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of…

Medium · published May 3, 2024

CVSS v3.1
5.5
EPSS
0%
Percentile
4.8
In the wild
Unconfirmed
What it is

An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization.

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00153 · 4.8th percentile
Weakness
CWE-927 · Use of Implicit Intent for Sensitive Communication
Published
2024-05-03T14:06Z
EPSS history
Timeline
  • 03 MAY 14:06Z
    An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of…
    cvelistv5