More information about this CVE will likely be available in a few days

Description


A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.

Related CPE's


Could not find any relations

Weaknesses


Could not find any weaknesses

CVSS impact metrics


Could not find any metrics

Information


Source identifier

[email protected]

Vulnerability status

Awaiting analysis

Published

2024-06-03T20:15:08.810

1 month ago

Last modified

2024-06-25T20:15:11.020

1 month ago