Vulnerabilities > CVE-2023-33293 - Exposure of Resource to Wrong Sphere vulnerability in Kaiostech Kaios 3.0/3.1

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
kaiostech
CWE-668

Summary

An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., myapp.localhost. An attacker can make fetch requests to api-deamon to determine if a given app is installed and read the manifest.webmanifest contents, including the app version.

Vulnerable Configurations

Part Description Count
OS
Kaiostech
2

Common Weakness Enumeration (CWE)