VYPR
Medium severity4.3NVD Advisory· Published Sep 9, 2024· Updated Jun 17, 2026

CVE-2024-45203

CVE-2024-45203

Description

Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Istyle/\@cosme2 versions
    cpe:2.3:a:istyle:\@cosme:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:istyle:\@cosme:*:*:*:*:*:android:*:*range: <5.69.0
    • cpe:2.3:a:istyle:\@cosme:*:*:*:*:*:iphone_os:*:*range: <=6.74.0
  • @cosme/@cosme Appllm-create
    Range: <5.69.0
  • Range: versions prior to 6.74.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.