CVE-2023-3612: Unprotected WebView access in Govee Home App
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3612.
What is the severity of CVE-2023-3612?
The severity of CVE-2023-3612 is high (8.2).
What is the affected software?
The affected software is the Govee Home app for Android (up to version 5.8.01) and iPhone OS (up to version 5.8.01).
What is the description of CVE-2023-3612?
CVE-2023-3612 is a vulnerability in the Govee Home app that allows unrestricted access to the WebView component, enabling potential execution of malicious JavaScript or phishing attacks.
Is there a fix available for CVE-2023-3612?
Currently, there is no information available about an official fix for CVE-2023-3612. It is recommended to update the Govee Home app to the latest version and exercise caution when accessing unknown or suspicious URLs.