PT-2025-5746 · Unknown · Mobile Security Framework

Oleg Surnin

·

Published

2025-02-05

·

Updated

2025-02-05

·

CVE-2025-24804

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Mobile Security Framework (MobSF) versions prior to 4.3.1
Description: The issue arises when an attacker manually modifies the CFBundleIdentifier value in the Info.plist file by adding special characters, which are not allowed according to Apple's documentation. This causes the application to encounter an error when parsing the incorrect characters in the bundle ID, resulting in a 500 error and preventing content from being displayed. The only way to resolve this is to manually remove the malicious application from the system.
Recommendations: For versions prior to 4.3.1, upgrade to version 4.3.1 to address the issue. As a temporary workaround, consider manually checking the uploaded bundle IDs against the regex to prevent the error. Additionally, restrict access to the urls.py file to minimize the risk of exploitation. Avoid using the CFBundleIdentifier value in the affected API endpoints until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-08880
CVE-2025-24804
GHSA-JRM8-XGF3-FWQR

Affected Products

Mobile Security Framework