CVE-2023-33293: Medium severity Kaiostech Kaios vulnerability
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on .localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33293?
CVE-2023-33293 is considered a high-severity vulnerability due to its potential for information disclosure and exploitation by attackers.
How do I fix CVE-2023-33293?
To fix CVE-2023-33293, upgrade KaiOS to the latest version that addresses the vulnerability as per the vendor's guidance.
What are the impacted versions in CVE-2023-33293?
CVE-2023-33293 impacts KaiOS versions 3.0 and 3.1.
What type of attack can exploit CVE-2023-33293?
CVE-2023-33293 can be exploited by an attacker making unauthorized fetch requests to the local web server to determine installed applications.
Is CVE-2023-33293 a remote or local vulnerability?
CVE-2023-33293 is a local vulnerability since it requires access to the device on which KaiOS is running.