Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.
- https://youtu.be/jWyDfEB0m08
- https://github.com/n0-traces/cve_monitor