216.73.217.50

CVE-2020-25900

· Published 05/06/2026 15:16 · Modified 05/06/2026 16:04

Labels: CVE-2020-25900 2026-06-05CVE-2020-25900CWE-359[email protected]

Essential information

Published
05/06/2026 15:16
Modified
05/06/2026 16:04
Author
Creator
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
hellotalk / hellotalk cpe:2.3:a:hellotalk:hellotalk:3.4.1:*:*:*:*:*:*:*

References