User Information Exposure in Baidu Lite App for iOS
CVE-2024-56952

6.5MEDIUM

Key Information:

Vendor

Baidu

Vendor
CVE Published:
27 January 2025

What is CVE-2024-56952?

A security issue in the Baidu Lite app for iOS version 6.40.0 permits malicious actors to exploit the application by leveraging specially crafted links. This vulnerability may enable attackers to gain unauthorized access to sensitive user information, posing significant privacy risks. Users are advised to remain vigilant and apply necessary updates as soon as they become available to mitigate potential threats.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.