CVE-2020-20094

MEDIUM

Instagram iOS < 106.0 and Android < 107.0.0.11 - URI Spoofing via RTLO Injection

Title source: llm
STIX 2.1

Description

Instagram iOS 106.0 and prior and Android 107.0.0.11 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/zadewg/RIUS
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/166448/RTLO-Injection-URI-Spoofing.html

Scores

CVSS v3 6.5
EPSS 0.0138
EPSS Percentile 68.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

Status published
Products (2)
facebook/instagram < 106.0
facebook/instagram < 107.0.0.11
Published Mar 23, 2022
Tracked Since Feb 18, 2026