CVE-2020-24653
Expo on iOS is insecure due incorrect security attribute application
EPSS 0.43%
Description
secure-store in Expo through 9.1.0 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
How to fix CVE-2020-24653
To remediate CVE-2020-24653, upgrade the affected package to a fixed version below.
- npm/expo—upgrade to 9.1.0 or later
Is CVE-2020-24653 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 9.1.0