Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Media ContentProvider URIs used for opening attachments in other apps were generated sequentially prior to WhatsApp for Android v2.20.185, which could have allowed a malicious third party app chosen to open the file to guess the URIs for previously opened attachments until the opener app is terminated.
CVSS Information
N/A
Vulnerability Type
可预测问题
Vulnerability Title
Facebook WhatsApp 安全特征问题漏洞
Vulnerability Description
Facebook WhatsApp是美国Facebook公司的一套利用网络传送短信的移动应用程序。该应用程序通过智能手机中的联络人信息,查找使用该软件的联络人传送文字、图片等。 基于Android的WhatsApp v2.20.185之前版本Media ContentProvider URIs存在安全漏洞,该漏洞源于其他应用中用于打开附件的Media ContentProvider uri之前被依次生成,这可能会让选择打开文件的恶意第三方应用猜测之前打开的附件的uri,直到打开的应用被终止。
CVSS Information
N/A
Vulnerability Type
N/A