Executive brief
Vivo EasyShare, a file-sharing application for mobile devices, contains a security flaw in its authentication process. An attacker on the same local network (such as public Wi-Fi) could exploit this weakness to bypass security checks and access sensitive user data. This could lead to the unauthorized exposure of personal files or information stored within the application.
Technical details
A missing authentication vulnerability (CWE-306) exists in the EasyShare module of Vivo mobile devices. The flaw resides in the authentication mechanism for a specific file-sharing feature, which fails to properly verify identities under certain local network conditions. An attacker positioned on the same adjacent network (e.g., WLAN) can exploit this to bypass access controls and cause unauthorized data leakage. The vulnerability requires minimal user interaction and is resolved in EasyShare version 7.0.11.5.
Affected products
- Vivo EasyShare Versions below 7.0.11.5
Timeline
- 2026-03-13: disclosed
- 2026-03-13: advisory
- 2026-03-13: patched