CVE-2015-1314 Information

Description

The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login which might allow physically proximate users to obtain banking account numbers and balances.

Reference

http://dnlongen.blogspot.com/2015/01/usaa-mobile-app-gives-away-your-account.html http://packetstormsecurity.com/files/130067/USAA-Mobile-App-Information-Disclosure.html http://seclists.org/fulldisclosure/2015/Jan/94

Share on: