First published: Mon Sep 14 2020(Updated: )
An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the Note application. At a bare minimum, this allows an attacker to take control over the Note application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KaiOS | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14761 is categorized as a medium severity vulnerability due to its potential for HTML and JavaScript injection.
CVE-2019-14761 allows a local attacker to inject arbitrary HTML into the pre-installed Note application, compromising its user interface.
CVE-2019-14761 affects KaiOS versions 2.5.
No, CVE-2019-14761 requires local access for exploitation, making it a local attack vector.
To mitigate CVE-2019-14761, users should avoid using the Note application and uninstall it if possible.