Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for Android
CVE-2023-41898

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
19 October 2023

What is CVE-2023-41898?

The Home Assistant Companion for Android app, an open-source home automation solution, is vulnerable to arbitrary URL loading in its WebView implementation. This vulnerability allows potential attackers to execute arbitrary JavaScript, gain limited access to native code, and steal user credentials. Users are strongly encouraged to upgrade to version 2023.9.2, where this issue has been addressed, as there are currently no known workarounds to mitigate the risks associated with this vulnerability. This issue is also logged as a GitHub Security Lab Vulnerability Report: GHSL-2023-142.

Affected Version(s)

core < 2023.9.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.