CVE-2024-28745

LOW

ABEMA App <10.65.0 - SSRF

Title source: llm
STIX 2.1

Description

Improper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing another app installed on the user's device to access an arbitrary URL on 'ABEMA' App for Android via Intent. If this vulnerability is exploited, an arbitrary website may be displayed on the app, and as a result, the user may become a victim of a phishing attack.

References (1)

Core 1
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN70640802/

Scores

CVSS v3 3.3
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-732
Status published
Products (1)
AbemaTV, Inc./'ABEMA' App for Android prior to 10.65.0
Published Mar 18, 2024
Tracked Since Feb 18, 2026