VYPR
Medium severity6.5NVD Advisory· Published Oct 24, 2022· Updated Jun 17, 2026

CVE-2022-41797

CVE-2022-41797

Description

Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:lemon8_project:lemon8:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:lemon8_project:lemon8:*:*:*:*:*:android:*:*range: <3.3.5
    • cpe:2.3:a:lemon8_project:lemon8:*:*:*:*:*:iphone_os:*:*range: <3.3.5
  • Lemon8/Lemon8llm-fuzzy
    Range: <3.3.5
  • ByteDance K.K./Lemon8 App for Android and Lemon8 App for iOSv5
    Range: Lemon8 App for Android versions prior to 3.3.5 and Lemon8 App for iOS versions prior to 3.3.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.