OTP Disclosure via Exported TokenContentProvider

0
7

CVSSv3 Score: 5.0

An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI.

Revised on 2026-05-12 00:00:00

– Read more