Vulnerability · NVD
CVE-2022-28799
HIGH 8.8
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
15.53%
moderate exploit risk
percentile 96.5%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| tiktok |
tiktok Android
|
Android | <23.7.3 | cpe:2.3:a:tiktok:tiktok:*:*:*:*:*:android:*:* |