PT-2023-25434 · Govee · Govee Home
Jan Adamski
·
Publicado
2023-09-11
·
Atualizado
2023-09-13
·
CVE-2023-3612
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Govee Home app (affected versions not specified)
Description
The Govee Home app has unprotected access to the WebView component, which can be opened by any app on the device. By sending a URL to a specially crafted site, an attacker can execute JavaScript in the context of WebView or steal sensitive user data by displaying phishing content.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Govee Home