PT-2023-25434 · Govee · Govee Home

Jan Adamski

·

Publicado

2023-09-11

·

Atualizado

2023-09-13

·

CVE-2023-3612

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Govee Home app (affected versions not specified)
Description The Govee Home app has unprotected access to the WebView component, which can be opened by any app on the device. By sending a URL to a specially crafted site, an attacker can execute JavaScript in the context of WebView or steal sensitive user data by displaying phishing content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3612

Produtos afetados

Govee Home