Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37456 | An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version. |
| Link | Providers |
|---|---|
| https://kaios.dev/cve/1410290 |
|
Tue, 21 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-21T15:14:19.375Z
Reserved: 2023-05-22T00:00:00.000Z
Link: CVE-2023-33293
Updated: 2024-08-02T15:39:36.109Z
Status : Modified
Published: 2023-05-22T16:15:10.567
Modified: 2024-11-21T08:05:21.227
Link: CVE-2023-33293
No data.
OpenCVE Enrichment
No data.
EUVD