CVE-2024-23727: Code Injection
The YI Smart Kami Vision com.kamivision.yismart application through 1.0.020231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23727?
CVE-2024-23727 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-23727?
To mitigate CVE-2024-23727, update the YI Smart Kami Vision application to the latest version beyond 1.0.0_20231219.
What types of exploits are possible with CVE-2024-23727?
CVE-2024-23727 allows remote attackers to execute arbitrary JavaScript code on affected devices.
Which versions of the YI Smart Kami Vision app are affected by CVE-2024-23727?
CVE-2024-23727 affects the YI Smart Kami Vision application versions up to and including 1.0.0_20231219.
What is the impact of CVE-2024-23727 on user privacy?
Exploitation of CVE-2024-23727 could lead to unauthorized access and manipulation of sensitive user data.