CVE-2025-20615

CVSS 3.1 Score 6.2 of 10 (medium)

Details

Published Feb 13, 2025
CWE ID 359

Summary

CVE-2025-20615 is a vulnerability affecting the Qardio Arm iOS application. The issue arises due to sensitive data, including usernames and passwords, being exposed in a plist file. An attacker can exploit this vulnerability, gaining access to production-level development accounts. Once inside, they can utilize an engineering backdoor that enables sending hex-based commands via a UI-based terminal. This puts user data at risk of unauthorized access and manipulation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share