We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/forse01/CVE-2020-11990-Cordova
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/soosmile/POC