OTP Disclosure via Exported TokenContentProvider

Summary

An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI.

Version Affected Solution
FortiTokenAndroid 6.4 Not affected Not Applicable
FortiTokenAndroid 6.2 6.2 all versions Migrate to a fixed release
FortiTokenAndroid 6.1 6.1 all versions Migrate to a fixed release
FortiTokenAndroid 5.2 5.2 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Renan Dias for reporting this vulnerability

Timeline

2026-05-12: Initial publication