Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns the user's call log without origin or permission checks. An attacker can inject a JavaScript payload that runs in a browser or app without user interaction or consent. This allows an attacker to send the user's call logs to a remote server via XMLHttpRequest or Fetch.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KaiOS 安全漏洞
Vulnerability Description
KaiOS是一个应用软件。用于智能功能手机的应用程序。 KaiOS 3.0版本存在安全漏洞,该漏洞源于无需来源或权限检查即可返回用户的通话记录,攻击者可以注入在浏览器或应用程序中运行的JavaScript有效载荷,将用户的调用日志发送到远程服务器。
CVSS Information
N/A
Vulnerability Type
N/A