CVE-2024-12993
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
30/12/2024
Last modified:
15/04/2026
Description
Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges. <br />
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM



