Govee Home app has unprotected access to WebView...
High severity
Unreviewed
Published
Sep 11, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 11, 2023
Published to the GitHub Advisory Database
Sep 11, 2023
Last updated
Apr 4, 2024
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.
References