MEDIUM
GHSA-rwx9-wqj8-vr77
Expo on iOS is insecure due incorrect security attribute application
Quick fix
GHSA-rwx9-wqj8-vr77 — expo: upgrade to the fixed version with the command below.
npm install expo@9.1.0Details
secure-store in Expo through 9.1.0 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-24653[ADVISORY]
- https://github.com/expo/expo/pull/9264[WEB]
- https://github.com/expo/expo/commit/1d82bf07fae2c96273e9189997e521359cffc1a9#diff-5b2820f378da980bd8a8185e2e1b2f9ce085d834534483f29c67932f282cc5c9[WEB]
- https://github.com/expo/expo[PACKAGE]
- https://github.com/expo/expo/blob/main/packages/expo-secure-store/CHANGELOG.md[WEB]