CVE-2023-3612
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2023
Last modified:
13/09/2023
Description
Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:govee:home:*:*:*:*:*:android:*:* | 5.8.01 (excluding) | |
| cpe:2.3:a:govee:home:*:*:*:*:*:iphone_os:*:* | 5.8.01 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



