Critical severity9.8NVD Advisory· Published Aug 26, 2020· Updated Jun 17, 2026
CVE-2020-24653
CVE-2020-24653
Description
secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
exponpm | < 9.1.0 | 9.1.0 |
Affected products
3- Expo/secure-storedescription
Patches
Vulnerability mechanics
References
5- github.com/expo/expo/pull/9264nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rwx9-wqj8-vr77ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-24653ghsaADVISORY
- github.com/expo/expo/blob/main/packages/expo-secure-store/CHANGELOG.mdghsaWEB
- github.com/expo/expo/commit/1d82bf07fae2c96273e9189997e521359cffc1a9ghsaWEB
News mentions
0No linked articles in our index yet.