CVE-2020-20094
MEDIUMInstagram iOS < 106.0 and Android < 107.0.0.11 - URI Spoofing via RTLO Injection
Title source: llmDescription
Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/zadewg/RIUS
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/166448/RTLO-Injection-URI-Spoofing.html
Scores
CVSS v3
6.5
EPSS
0.0138
EPSS Percentile
68.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
Status
published
Products (2)
facebook/instagram
< 106.0
facebook/instagram
< 107.0.0.11
Published
Mar 23, 2022
Tracked Since
Feb 18, 2026