CVE-2021-27549
Severity CVSS v4.0:
Pending analysis
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
22/02/2021
Last modified:
03/08/2024
Description
Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screen
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:genymobile:genymotion_desktop:*:*:*:*:*:-:*:* | 3.2.0 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://docs.genymotion.com/desktop/latest/02_Application.html
- https://github.com/eybisi/misc/tree/main/clipwatch
- https://twitter.com/0xabc0/status/1363788023956185090
- https://twitter.com/0xabc0/status/1363855602477387783
- https://twitter.com/0xabc0/status/1363856804602671104
- https://www.genymotion.com/download/
- https://www.youtube.com/watch?v=Tod8Q6sf0P8



