nic-delhi / AarogyaSetu_Android

Aarogya Setu Android app native code
https://www.aarogyasetu.gov.in/
Other
2.88k stars 1.85k forks source link

play core library version update to 1.7.2 #531

Open vikaskchoubey opened 3 years ago

vikaskchoubey commented 3 years ago

A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. I believe that we are using the vulnerable play core version(1.6.0) in our android apk.so update the play core to the 1.7.2