First published: Tue Dec 03 2024(Updated: )
Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
GamingHub | <6.1.03.4 | |
GamingHub | <7.1.02.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49418 is classified as a high severity vulnerability due to insufficient verification of URL authenticity.
To fix CVE-2024-49418, update GamingHub to version 6.1.03.4 or later for Korea or 7.1.02.4 or later for Global.
CVE-2024-49418 can be exploited by remote attackers to enable JavaScript in the webview, potentially leading to malicious activities.
CVE-2024-49418 affects GamingHub versions prior to 6.1.03.4 for Korea and 7.1.02.4 for Global.
Yes, user data can be at risk because the vulnerability allows remote attackers to manipulate JavaScript execution within the app.