Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KaiOS 安全漏洞
Vulnerability Description
KaiOS是一个应用软件。用于智能功能手机的应用程序。 KaiOS 3.0和3.1版本存在安全漏洞,该漏洞源于二进制公开服务器信息,攻击者利用该漏洞可以读取特定信息。
CVSS Information
N/A
Vulnerability Type
N/A