Sept. 11, 2023, 10:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

access app attacker context cve data device home javascript phishing sensitive steal url user data webview

SAP Security Administrator

@ FARO Technologies | Americas-US-Lake Mary-125 Bldg

Cloud Security Engineer, Specialist

@ Vanguard | Malvern, PA

Cybersecurity Assessment and Authorization Specialist

@ Booz Allen Hamilton | USA, MD, Bethesda (9000 Rockville Pike)

Network Security Specialist

@ IAG GBS | Madrid, Spain

Information System Security Officer

@ CSEngineering | Nellis Air Force Base, NV, USA

Senior Consultant, Risk and Governance

@ CIBC | Toronto-CC East 11th Floor