VYPR
Unrated severityNVD Advisory· Published Jul 15, 2021· Updated Aug 4, 2024

CVE-2020-12731

CVE-2020-12731

Description

The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The MagicMotion Flamingo 2 Android app stores sensitive data on the external SD card in a world-readable directory, allowing other apps to access it.

Vulnerability

The MagicMotion Flamingo 2 application for Android stores data on the device's external SD card under the directory com.vt.magicmotion/files/Pictures. This directory is world-readable, meaning any other application installed on the device with the READ_EXTERNAL_STORAGE permission can access its contents. The vulnerability affects all versions of the Flamingo 2 app as described in the vendor's product page [1].

Exploitation

An attacker needs to have a malicious or otherwise untrusted application installed on the same Android device that has been granted the READ_EXTERNAL_STORAGE permission. The attacker's app can then read the contents of com.vt.magicmotion/files/Pictures without any additional authentication or user interaction beyond the initial permission grant. No special network position or race condition is required.

Impact

Successful exploitation leads to unauthorized disclosure of pictures stored by the Flamingo 2 app. Given the nature of the application (a wearable intimate device controller), these pictures are likely to be sensitive personal images. The attacker gains read access to these files but does not achieve code execution, privilege escalation, or modification of data.

Mitigation

As of the publication date (2021-07-15), no official fix or updated version has been released by MagicMotion to address this issue. Users are advised to uninstall the Flamingo 2 app if sensitive data is stored, or to avoid storing such data on the device. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.