Medium severity4.3NVD Advisory· Published Jun 11, 2020· Updated Jun 17, 2026
CVE-2020-13702
CVE-2020-13702
Description
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary temporary UID. An attacker with access to Beacon or IoT networks can seamlessly track individual device movement via a Bluetooth LE discovery mechanism.
Affected products
3- cpe:2.3:a:the_rolling_proximity_identifier_project:the_rolling_proximity_identifier:*:*:*:*:*:*:*:*Range: <=2020-05-29
- Apple/Google/Exposure Notification APIdescription
- Range: <=2020-05-29
Patches
Vulnerability mechanics
References
3- github.com/google/exposure-notifications-internals/commit/8f751a666697nvdPatchThird Party Advisory
- github.com/google/exposure-notifications-internals/commit/8f751a666697c3cae0a56ae3464c2c6cbe31b69envdPatchThird Party Advisory
- blog.google/documents/70/Exposure_Notification_-_Bluetooth_Specification_v1.2.2.pdfnvdThird Party Advisory
News mentions
0No linked articles in our index yet.