VYPR
Critical severity9.8NVD Advisory· Published Aug 26, 2020· Updated Jun 17, 2026

CVE-2020-24653

CVE-2020-24653

Description

secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
exponpm
< 9.1.09.1.0

Affected products

3
  • cpe:2.3:a:expo:expo:*:*:*:*:*:iphone_os:*:*
    Range: <=2.16.1
  • Expo/secure-storedescription
  • ghsa-coords
    Range: < 9.1.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.