CVE-2023-33293

CVSS V2 None CVSS V3 None
Description
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version.
Overview
  • CVE ID
  • CVE-2023-33293
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Awaiting Analysis
  • Published Version
  • 2023-05-22T16:15:10
  • Last Modified Date
  • 2023-05-22T16:15:51
References
Reference URL Reference Tags
https://kaios.dev/cve/1410290
History
Created Old Value New Value Data Type Notes
2023-05-22 17:01:40 Added to TrackCVE