• Product: VLC for Mobile IOS
  • Vendor: VideoLAN/Open Source
  • Software Version: 3.1.4 Below Category: Permissions, Privileges, and Access Control (CWE-264)
  • Vendor Notified: 2018-11-26 11:00 PM
  • Patched: 2018-12-21
  • Disclosed: 2019-01-01
  • Researcher(s): Christian Angel
  • CVE: 2018-19937

References

https://apps.apple.com/ms/app/vlc-for-mobile/id650377962

https://github.com/videolan/vlc-ios/pull/178/commits/d84d7c0a94eb7fba202d2c5fc3739276d2d3986f

https://nvd.nist.gov/vuln/detail/CVE-2018-19937