First published: Mon Sep 14 2020(Updated: )
An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Recorder application. At a bare minimum, this allows an attacker to take control over the Recorder application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KaiOS | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14760 is classified as a high severity vulnerability due to the potential for arbitrary HTML and JavaScript injection.
To mitigate CVE-2019-14760, ensure that the affected version of KaiOS is updated to a secure release that addresses the vulnerability.
Users of KaiOS version 2.5 are directly affected by CVE-2019-14760 due to the vulnerability in the pre-installed Recorder application.
CVE-2019-14760 can be exploited through local attacks that leverage HTML and JavaScript injection into the Recorder application's user interface.
CVE-2019-14760 specifically affects the Recorder application, but similar vulnerabilities may exist in other pre-installed applications in KaiOS.