<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 23:27:13 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-12993 — Location information exposure in Infinix Weather app</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-12993</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Infinix Mobile com.rlk.weathers&lt;/p&gt;
&lt;p&gt;Infinix devices contain a pre-loaded &amp;#34;com.rlk.weathers&amp;#34; application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges. 
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Infinix Mobile com.rlk.weathers&lt;/p&gt;
&lt;p&gt;Infinix devices contain a pre-loaded &amp;#34;com.rlk.weathers&amp;#34; application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location without any privileges. 
After multiple attempts to contact the vendor we did not receive any answer. We suppose this issue affects all Infinix Mobile devices.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-12993</guid>
    </item>
  </channel>
</rss>
