JVN#70640802
"ABEMA" App for Android fails to restrict access permissions
Overview
"ABEMA" App for Android provided by AbemaTV, Inc. fails to restrict access permissions.
Products Affected
- "ABEMA" App for Android versions prior to 10.65.0
Description
"ABEMA" App for Android provided by AbemaTV, Inc. fails to restrict access permissions (CWE-926) that allows another app installed on the user's device to access an arbitrary URL on "ABEMA" App via Intent.
Impact
An arbitrary website may be displayed on the app, and as a result, the user may become a victim of a phishing attack.
Solution
Update the Application
Update the application to the latest version according to the information provided by the developer.
The developer has released the following version that fixes the vulnerability.
- "ABEMA" App for Android 10.65.0
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
Access Vector(AV) | Local (L) | Adjacent Network (A) | Network (N) |
---|---|---|---|
Access Complexity(AC) | High (H) | Medium (M) | Low (L) |
Authentication(Au) | Multiple (M) | Single (S) | None (N) |
Confidentiality Impact(C) | None (N) | Partial (P) | Complete (C) |
Integrity Impact(I) | None (N) | Partial (P) | Complete (C) |
Availability Impact(A) | None (N) | Partial (P) | Complete (C) |
Credit
Shiga Takuma of BroadBand Security, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2024-28745 |
JVN iPedia |
JVNDB-2024-000031 |