Unrated severityNVD Advisory· Published May 22, 2023· Updated Jan 21, 2025
CVE-2023-33293
CVE-2023-33293
Description
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- KaiOS/KaiOSdescription
Patches
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.