OTP Disclosure via Exported TokenContentProvider
Summary
An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI.
| Version | Affected | Solution |
|---|---|---|
| FortiTokenAndroid 6.4 | Not affected | Not Applicable |
| FortiTokenAndroid 6.2 | 6.2 all versions | Migrate to a fixed release |
| FortiTokenAndroid 6.1 | 6.1 all versions | Migrate to a fixed release |
| FortiTokenAndroid 5.2 | 5.2 all versions | Migrate to a fixed release |
Acknowledgement
Fortinet is pleased to thank Renan Dias for reporting this vulnerabilityTimeline
2026-05-12: Initial publication