PT-2023-5310 · Unknown · Warp Mobile Client

Hackerrishad

·

Published

2023-08-29

·

Updated

2023-09-01

·

CVE-2023-0238

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions WARP Mobile Client versions <=6.29
Description The issue is related to the lack of a security policy in the WARP Mobile Client for Android, which allows a malicious app installed on a victim's device to exploit a peculiarity in an Android function. This can enable the malicious app to dictate the task behavior of the WARP app, potentially allowing access to confidential information and arbitrary functions within the application.
Recommendations For versions <=6.29, update to a version that includes a security policy to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-05936
CVE-2023-0238
GHSA-23RX-F69W-G75C

Affected Products

Warp Mobile Client