First published: Mon Sep 09 2024(Updated: )
Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Istyle @cosme | <5.69.0 | |
iStyle @cosme iPhone OS | <=6.74.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45203 is classified as a high severity vulnerability due to its potential for unauthorized access to external websites.
To fix CVE-2024-45203, update the @cosme app on Android to version 5.69.0 or later and on iOS to version 6.74.0 or later.
CVE-2024-45203 allows attackers to trick users into accessing arbitrary websites through the vulnerable app.
CVE-2024-45203 affects @cosme app versions prior to 5.69.0 for Android and prior to 6.74.0 for iOS.
Currently, there is no known workaround for CVE-2024-45203 other than upgrading to the latest app versions.