First published: Wed Dec 18 2019(Updated: )
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Shazam | =9.25.0 | |
Google Android | ||
Apple Shazam | =12.11.0 | |
Apple iPhone OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8792 is classified as a moderate severity vulnerability due to its potential for arbitrary JavaScript code execution through specially crafted URLs.
To resolve CVE-2019-8792, update the Shazam app to version 9.25.0 on Android or version 12.11.0 on iOS.
CVE-2019-8792 specifically affects Shazam app versions prior to 9.25.0 on Android and 12.11.0 on iOS.
CVE-2019-8792 can be exploited by processing a maliciously crafted URL that may lead to arbitrary JavaScript code execution.
Yes, the permanent fix for CVE-2019-8792 is implemented in the updated versions of the Shazam app.