VYPR
Unrated severityNVD Advisory· Published Sep 11, 2023· Updated Sep 26, 2024

Unprotected WebView access in Govee Home App

CVE-2023-3612

Description

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.