← Back

Expo

expo

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Expo
1Expo Software Development Kit
Jun 17, 2026
Apr 24, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achi...Show more
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).Show less
1Expo
1Expo
Jun 17, 2026
Aug 26, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.