Improper Deep Link Validation in McAfee Security Antivirus VPN for Android
CVE-2024-34405
9.1CRITICAL
Key Information:
- Vendor
McAfee
- Vendor
- CVE Published:
- 11 June 2024
What is CVE-2024-34405?
A vulnerability in McAfee Security: Antivirus VPN for Android prior to version 8.3.0 exposes users to potential risks by allowing an attacker to execute arbitrary URLs within the app. This improper validation of deep links can lead to various security risks, including unauthorized access and manipulation of user data, making it crucial for users to update their applications promptly to the latest version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved