The GarminOS TVM component in CIQ API version 2.1.0...
Critical severity
Unreviewed
Published
May 23, 2023
to the GitHub Advisory Database
•
Updated Jan 31, 2025
Description
Published by the National Vulnerability Database
May 23, 2023
Published to the GitHub Advisory Database
May 23, 2023
Last updated
Jan 31, 2025
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the
Toybox.SensorHistory
module without permission. A malicious application could call any functions from theToybox.SensorHistory
module without the user's consent and disclose potentially private or sensitive information.References