Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's device.
History

Thu, 05 Dec 2024 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 03:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's device.
Weaknesses CWE-939
References
Metrics cvssV3_0

{'score': 3.6, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-12-05T11:33:27.693Z

Reserved: 2024-11-27T08:11:25.031Z

Link: CVE-2024-54014

cve-icon Vulnrichment

Updated: 2024-12-05T11:33:15.432Z

cve-icon NVD

Status : Received

Published: 2024-12-05T03:15:14.530

Modified: 2024-12-05T03:15:14.530

Link: CVE-2024-54014

cve-icon Redhat

No data.