Medium severity5.3NVD Advisory· Published May 22, 2023· Updated Jun 17, 2026
CVE-2023-33293
CVE-2023-33293
Description
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- KaiOS/KaiOSdescription
Patches
Vulnerability mechanics
References
1- kaios.dev/cve/1410290nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.