Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g545-rmg6-689p

Опубликовано: 03 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controller JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to takeover another user's account and read her/his chat messages.

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controller JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to takeover another user's account and read her/his chat messages.

EPSS

Процентиль: 76%
0.00917
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-444
CWE-79

Связанные уязвимости

CVSS3: 9.6
nvd
больше 1 года назад

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.

EPSS

Процентиль: 76%
0.00917
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-444
CWE-79