PT-2023-28361 · Unknown · Wave.Ai.Browser
Edward Warren
·
Published
2023-09-11
·
Updated
2023-09-13
·
CVE-2023-42471
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wave.ai.browser application through 1.0.35 for Android
Description
The issue allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the
wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).Recommendations
For wave.ai.browser application through 1.0.35 for Android, consider disabling the
wave.ai.browser.ui.splash.SplashScreen activity until a patch is available to prevent exploitation. Restrict access to the WebView component to minimize the risk of arbitrary JavaScript code execution. Avoid using intents from untrusted sources to prevent passing malicious data to the application.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wave.Ai.Browser