Govee Home app has unprotected... CVE-2023-3612

- AV AC AU C I A
发布: 2023-09-11
修订: 2023-09-13

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息