Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2022-28799

CVE-2022-28799, high severity (CVSS 8.8): 1 tracked app concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
8.8

NVD scale

Exploitation
16.0 %

EPSS, predicted over 30 days

Tracked apps
1
Still exposed
0

The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 16.03% moderate exploit risk percentile 96.8%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • TikTok Android com.zhiliaoapp.musically
    Affected <23.7.3 Fixed in 23.7.3 Latest tracked 46.9.3 patched
    Observed affected builds (1)
Vulnerable CPE configurations (1)
Vendor Product Versions
tiktok tiktok
Android
<23.7.3
View on NVD ↗

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM