← Back to CVE List

CVE-2023-3612

Published: 2023-09-11T10:15Z
Last Modified: 2024-11-21T08:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt