Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
侵犯隐私
Vulnerability Title
HelloTalk 安全漏洞
Vulnerability Description
HelloTalk是中国HelloTalk公司的一款语言交换与社交学习应用。 HelloTalk 3.4.1及之前版本存在安全漏洞,该漏洞源于存储全精度GPS坐标,即使用户仅打算共享国家或城市,这些坐标也会被放入其他用户客户端的数据库中。
CVSS Information
N/A
Vulnerability Type
N/A