CVE-2020-7705
This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters and NSURLProtocol methods along with anti-debug and proxy detection protection. If those hooks are active MintegralAdSDK sends obfuscated data about every opened URL in an application to their servers. Note that the malicious functionality is enabled even if the SDK was not enabled to serve ads.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.17%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-1021
Referencias
- https://snyk.io/blog/sourmint-malicious-code-ad-fraud-and-data-leak-in-ios/
- https://snyk.io/research/sour-mint-malicious-sdk/
- https://snyk.io/vuln/SNYK-COCOAPODS-MINTEGRALADSDK-598852
- https://snyk.io/blog/sourmint-malicious-code-ad-fraud-and-data-leak-in-ios/
- https://snyk.io/research/sour-mint-malicious-sdk/
- https://snyk.io/vuln/SNYK-COCOAPODS-MINTEGRALADSDK-598852
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7705",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "MintegralAdSDK",
"versions": [
{
"status": "affected",
"version": "0.0.0",
"lessThan": "unspecified",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-08-24T18:15:10.143",
"references": [
{
"url": "https://snyk.io/blog/sourmint-malicious-code-ad-fraud-and-data-leak-in-ios/",
"tags": [
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/research/sour-mint-malicious-sdk/",
"tags": [
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-COCOAPODS-MINTEGRALADSDK-598852",
"tags": [
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/blog/sourmint-malicious-code-ad-fraud-and-data-leak-in-ios/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/research/sour-mint-malicious-sdk/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-COCOAPODS-MINTEGRALADSDK-598852",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-1021"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This affects the package MintegralAdSDK from 0.0.0. The SDK distributed by the company contains malicious functionality that tracks any URL opened by the app and reports it back to the company, along with performing advertisement attribution fraud. Mintegral can remotely activate hooks on the UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters and NSURLProtocol methods along with anti-debug and proxy detection protection. If those hooks are active MintegralAdSDK sends obfuscated data about every opened URL in an application to their servers. Note that the malicious functionality is enabled even if the SDK was not enabled to serve ads."
},
{
"lang": "es",
"value": "Esto afecta al paquete MintegralAdSDK desde la versión 0.0.0. El SDK distribuido por la empresa contiene una funcionalidad maliciosa que rastrea cualquier URL abierta por la aplicación y la reporta a la empresa, además de llevar a cabo un fraude de atribución publicitaria. Mintegral puede remotamente activar hooks en los métodos UIApplication, openURL, SKStoreProductViewController, loadProductWithParameters y NSURLProtocol junto con la protección de detección de proxy y anti-debug. Si esos hooks están activos, MintegralAdSDK envía datos ofuscados sobre cada URL abierta en una aplicación hacia sus servidores. Tome en cuenta que la funcionalidad maliciosa está habilitada incluso si el SDK no estaba habilitado para publicar anuncios."
}
],
"lastModified": "2026-06-17T03:25:17.910",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mintegral:mintegraladsdk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3713524-33F9-462A-8FC0-BE573B08DA10",
"versionStartIncluding": "0.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}