Security Advisory

CVE-2019-13096

9.8
CRITICAL

Vulnerability Description

TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/.xml to gain unauthorized access.
Published Date July 22, 2019
Official Source NIST NVD Advisory