HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://isopach.dev/CVE-2020-25900/ |
|
History
Fri, 05 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.) | |
| Weaknesses | CWE-359 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-05T13:48:00.291Z
Reserved: 2020-09-24T00:00:00.000Z
Link: CVE-2020-25900
No data.
Status : Received
Published: 2026-06-05T15:16:39.230
Modified: 2026-06-05T15:16:39.230
Link: CVE-2020-25900
No data.
OpenCVE Enrichment
No data.