CVE-2024-12993

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
30/12/2024
Last modified:
15/04/2026

Description

Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges. <br /> After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.