CVE Published: 19/06/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: jpcert |
Vendor: ZOZO, Inc. |
Product: \'ZOZOTOWN\' App for Android Status : PUBLISHED
CVE-2024-35298 Description
Improper authorization in handler for custom URL scheme issue in \'ZOZOTOWN\' App for Android versions prior to 7.39.6 allows an attacker to lead a user to access an arbitrary website via another application installed on the user\'s device. As a result, the user may become a victim of a phishing attack.