CVE-2024-34405
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
11/06/2024
Last modified:
15/04/2026
Description
Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.html
- https://www.mcafee.com/support/?page=shell&shell=article-view&articleId=000002403
- https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.html
- https://www.mcafee.com/support/?page=shell&shell=article-view&articleId=000002403



