RSSAmplifier

Home - Tom Barrasso · May 22, 2023

CVE-2023-33293

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

A vulnerability (CVSS 5.3) in KaiOS 3.0 and 3.1 where the /system/kaios/api-daemon binary exposes a local web server on *.localhost with subdomains for each installed application, allowing attackers to determine which apps are installed and access their manifest.webmanifest contents.

Read on barrasso.me

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.