First published: Mon May 01 2023(Updated: )
An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns the user's call log without origin or permission checks. An attacker can inject a JavaScript payload that runs in a browser or app without user interaction or consent. This allows an attacker to send the user's call logs to a remote server via XMLHttpRequest or Fetch.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KaiOS | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27108 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive user data.
To fix CVE-2023-27108, update KaiOS to the latest version that addresses this vulnerability.
CVE-2023-27108 can be exploited through JavaScript injection attacks that access the user's call log without permissions.
CVE-2023-27108 specifically affects devices running KaiOS version 3.0.
Yes, CVE-2023-27108 significantly compromises user privacy by exposing call logs without user consent.