CVE-2024-46939: Vivo Game Extension Engine

Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite local specific files

Affected products

  • Vivo Game Extension Engine: before 1.2.7.0 (fixed in 1.2.7.0)

Published 2024-11-28. Last modified 2026-06-17.