Skip to content

Direct Request ('Forced Browsing') in com.zhiliaoapp.musically can lead to user account hijacking

High
Ch0pin published GHSA-v39p-88q5-5cvr May 30, 2022

Package

com.zhiliaoapp.musically (Android)

Affected versions

< 23.7.3

Patched versions

23.7.3

Description

Impact

A crafted URI can force a WebView of the com.zhiliaoapp.musically Android Application to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface and hijack a user's account.

Patches

It is recommended to update to version 23.7.3 or above.

Workarounds

No workaround available

References

HackerOne disclosure

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2022-28799

Weaknesses