<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:37:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-230833</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-230833</link>
      <description>EUVD-2026-230833</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-230833</guid>
    </item>
    <item>
      <title>fkie_cve-2022-40703</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-40703</link>
      <description>&lt;p&gt;CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior&lt;/p&gt;
&lt;p&gt;on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior&lt;/p&gt;
&lt;p&gt;on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-40703</guid>
    </item>
    <item>
      <title>GHSA-65jr-q7fr-5gcv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-65jr-q7fr-5gcv</link>
      <description>&lt;p&gt;CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on Android allows an unauthenticated attacker with physical access to the Android device containing the app to bypass application authentication and alter information in the app.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-65jr-q7fr-5gcv</guid>
    </item>
    <item>
      <title>gsd-2022-40703</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-40703</link>
      <description>gsd-2022-40703</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-40703</guid>
    </item>
    <item>
      <title>ICSMA-22-298-01 — AliveCor KardiaMobile</title>
      <link>https://cve.radiocsirt.org/vuln/icsma-22-298-01</link>
      <description>&lt;p&gt;The smartphone application for the affected product is vulnerable to the publicly known Intent Manipulation exploit on Android phones. This exploit allows attackers to bypass app authentication and view or alter information in the app. The physical IoT device of the affected product has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient electrocardiography (EKG) results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphones ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The smartphone application for the affected product is vulnerable to the publicly known Intent Manipulation exploit on Android phones. This exploit allows attackers to bypass app authentication and view or alter information in the app. The physical IoT device of the affected product has no encryption for its data-over-sound protocols. Exploiting this vulnerability could allow an attacker to read patient electrocardiography (EKG) results or create a denial-of-service condition by emitting sounds at similar frequencies as the device, disrupting the smartphone microphones ability to accurately read the data. To carry out this attack, the attacker must be close (less than 5 feet) to pick up and emit sound waves.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsma-22-298-01</guid>
    </item>
  </channel>
</rss>
