PT-2024-22554 · Unknown · Abema App For Android

·

CVE-2024-28745

·

Published

2024-03-17

·

Updated

2024-11-19

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ABEMA App for Android versions prior to 10.65.0
Description The issue exists due to the improper export of Android application components, allowing another app installed on the user's device to access an arbitrary URL on the ABEMA App for Android via Intent. If exploited, an arbitrary website may be displayed on the app, potentially leading to phishing attacks.
Recommendations For versions prior to 10.65.0, update to version 10.65.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of Intents to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28745

Affected Products

Abema App For Android