Sensitive Data Exposure in Haokan Video iOS App by Baidu
CVE-2024-56954

6.5MEDIUM

Key Information:

Vendor

Baidu

Vendor
CVE Published:
27 January 2025

What is CVE-2024-56954?

A vulnerability has been identified within the Haokan Video iOS application, allowing malicious actors to access sensitive user information. By supplying a specially crafted link, attackers can exploit this flaw, potentially leading to significant data breaches and privacy concerns for users. This situation underscores the importance of rigorous security protocols in mobile applications to safeguard personal information against unauthorized access.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.