CVE-2023-3612 Information
Sep 16, 2023
cve
Description
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://www.sk-cert.sk/threat/sk-cert-bezpecnostne-varovanie-v20230811-10
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: