CVE-2023-51219

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.
Configurations

No configuration.

History

12 Nov 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-444

25 Jun 2024, 20:15

Type Values Removed Values Added
References
  • () https://news.ycombinator.com/item?id=40776880 -
Summary (en) A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controller JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to takeover another user's account and read her/his chat messages. (en) A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.

04 Jun 2024, 16:57

Type Values Removed Values Added
Summary
  • (es) Un problema de validación de enlace profundo en KakaoTalk 10.4.3 permitió que un adversario remoto dirigiera a los usuarios a ejecutar cualquier JavaScript controlador de atacante dentro de un WebView. El impacto se intensificó aún más al activar otro WebView que filtró su token de acceso en un encabezado de solicitud HTTP. En última instancia, este token de acceso podría usarse para hacerse cargo de la cuenta de otro usuario y leer sus mensajes de chat.

03 Jun 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-03 20:15

Updated : 2024-11-12 20:35


NVD link : CVE-2023-51219

Mitre link : CVE-2023-51219

CVE.ORG link : CVE-2023-51219


JSON object : View

Products Affected

No product.

CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')