The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 20 Aug 2024 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:heytap:internet_browser:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Heytap
Heytap internet Browser
Weaknesses CWE-79
CPEs cpe:2.3:a:heytap:internet_browser:45.10.3.4.1:*:*:*:*:android:*:*
Vendors & Products Heytap
Heytap internet Browser
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Mon, 19 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
Description The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-20T20:33:51.247Z

Reserved: 2024-01-21T00:00:00

Link: CVE-2024-23729

cve-icon Vulnrichment

Updated: 2024-08-20T20:31:26.751Z

cve-icon NVD

Status : Modified

Published: 2024-08-19T19:15:07.867

Modified: 2024-08-20T21:35:01.253

Link: CVE-2024-23729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.