The TikTok application before 23.7.3... CVE-2022-28799

6.8 AV AC AU C I A
发布: 2022-06-02
修订: 2024-11-21

The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息