Facebook for Android contains a flaw that may lead to unauthorized disclosure of potentially sensitive information. The issue is triggered by the continuation_intent being called with the permissions of the facebook application. This may allow a local attacker to gain access to potentially sensitive information stored in the /data/data/com.facebook.katana directory.
Disclosure Timeline:
Vendor Informed Date :2012-01-21
Vendor Solution Date :2012-02-02
Exploit Publish Date :2013-01-07
Disclosure Date :2013-01-07
Time to Patch :12 days