VYPR
Unrated severityNVD Advisory· Published Jun 17, 2020· Updated Aug 4, 2024

CVE-2020-6869

CVE-2020-6869

Description

ZTEMarket APK up to v10.06 exposes an Activity component, allowing local attackers to steal private cookies and perform silent app installations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ZTEMarket APK up to v10.06 exposes an Activity component, allowing local attackers to steal private cookies and perform silent app installations.

Vulnerability

ZTEMarket APK versions up to and including 10.06 expose an Activity component, enabling an information leak. The component is accessible without proper permission checks. This vulnerability exists in the Android application and is identified in the ZTE advisory as affecting all versions prior to 10.07 [1].

Exploitation

An attacker with local access to the device (i.e., the ability to launch activities on the affected application) can exploit the exposed Activity component to retrieve private cookies. The attack requires the user to have the ZTEMarket app installed. No other special privileges or user interaction beyond launching the malicious intent is needed [1].

Impact

Successful exploitation allows the attacker to obtain private cookies, leading to information disclosure of session data. Additionally, the attacker can execute silent installation of applications without the user's consent, which compromises the integrity and confidentiality of the device [1].

Mitigation

The vulnerability is fixed in ZTEMarket APK version 10.07, released according to the vendor's security bulletin on June 17, 2020. Users are advised to update to version 10.07 or later. No workarounds are provided for older versions [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.