CVE-2024-54014: Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and...

3.6 CVSS

Description

Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's device.

Classification

CVE ID: CVE-2024-54014

CVSS Base Severity: LOW

CVSS Base Score: 3.6

Affected Products

Vendor: SKYLARK HOLDINGS CO., LTD.

Product: 'Skylark' App for Android

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://play.google.com/store/apps/details?id=jp.co.skylark.app.gusto
https://apps.apple.com/jp/app/%E3%81%99%E3%81%8B%E3%81%84%E3%82%89%E3%83%BC%E3%81%8F%E3%82%A2%E3%83%97%E3%83%AA/id906930478
https://jvn.jp/en/jp/JVN03447226/

Timeline