The Citytv Video Android and iOS applications send potentially sensitive information such as device model and resolution, mobile carrier, days since first use, days since last use, total number of app launches, number of app launches since upgrade, and previous app session length, unencrypted to third party sites (Adobe Experience Cloud, ScorecardResearch). Citytv Video Android versions 4.08.0 and below and iOS versions 3.36 and below are affected.
69868f6b911d6cf596e7530e83a2e402a3944a8e2a68aa35eb11626d610a6c15
Citytv Video Android & iOS Applications - Unencrypted Analytics (CVE-2020-8507)
--
https://www.info-sec.ca/advisories/Citytv-Video.html
Overview
"The Citytv App is your free on-the-go and on-demand app featuring your favourite shows"
(https://play.google.com/store/apps/details?hl=en&id=com.rogers.citytv.phone)
(https://apps.apple.com/ca/app/citytv-video/id390492092)
Issue
The Citytv Video Android & iOS applications (Android version 4.08.0 and below, iOS version 3.36 and below) sends potentially sensitive information such as device model & resolution, mobile carrier, days since first use, days since last use, total number of app launches, number of app launches since upgrade, and previous app session length, unencrypted to third party sites (Adobe Experience Cloud, ScorecardResearch).
Impact
An attacker who can monitor network traffic could capture potentially sensitive information about the user's device and viewing habits without their knowledge.
Timeline
October 7, 2019 - Provided additional information about my research on unencrypted analytics to Apple via product-security@apple.com
October 17, 2019 - Attempted to obtain a security contact via a City TV support form
October 22, 2019 - Provided the details to the Adobe PSIRT via psirt@adobe.com and asked for assistance contacting the vendor
November 14, 2019 - Attempted to obtain a security contact via an email to mobile@rogersdigitalmedia.com
Solution
The Citytv Video Android & iOS applications as of February 4, 2020 are affected.
CVE-ID:
CVE-2020-8507