Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for Android
CVE-2023-41898
8.6HIGH
What is CVE-2023-41898?
The Home Assistant Companion for Android app, an open-source home automation solution, is vulnerable to arbitrary URL loading in its WebView implementation. This vulnerability allows potential attackers to execute arbitrary JavaScript, gain limited access to native code, and steal user credentials. Users are strongly encouraged to upgrade to version 2023.9.2, where this issue has been addressed, as there are currently no known workarounds to mitigate the risks associated with this vulnerability. This issue is also logged as a GitHub Security Lab Vulnerability Report: GHSL-2023-142.
Affected Version(s)
core < 2023.9.2
