PT-2023-25434 · Govee · Govee Home

Jan Adamski

·

Published

2023-09-11

·

Updated

2023-09-13

·

CVE-2023-3612

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Govee Home app (affected versions not specified)
Description The Govee Home app has unprotected access to the WebView component, which can be opened by any app on the device. By sending a URL to a specially crafted site, an attacker can execute JavaScript in the context of WebView or steal sensitive user data by displaying phishing content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-3612

Affected Products

Govee Home