Unprotected WebView access in Govee Home App
CVE-2023-3612
What is CVE-2023-3612?
A significant vulnerability exists in the Govee Home app that allows unauthorized access to its WebView component. This can be opened by any app on the user's device, creating a risk for data security. By manipulating the WebView, attackers can redirect users to malicious websites, where they may execute JavaScript to extract sensitive information or present phishing content to unsuspecting users. This flaw poses severe implications for user privacy and security, as attackers can exploit it to gather personal data or deceive users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Govee Home Android 5.7.03 < 5.8.01
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
