Executive brief
Vivo PcSuite, a tool used to manage mobile devices from a computer, contains a security flaw in its authentication process. An attacker within Bluetooth range could exploit this defect to bypass security checks and access sensitive information from the connected device. This could lead to the unauthorized exposure of personal data or files stored on the phone.
Technical details
A missing authentication vulnerability (CWE-306) exists in a specific function of Vivo PcSuite. The flaw resides in the authentication mechanism used during device-to-PC communication. An unauthenticated attacker within Bluetooth range (Adjacent vector) can exploit this defect to bypass security controls. Successful exploitation allows the attacker to leak sensitive information or potentially modify data on the target device. The vulnerability is addressed in PcSuite version 6.2.5.
Affected products
- Vivo PcSuite Versions below 6.2.5
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory
- 2026-06-12: patched: Fixed in version 6.2.5