CVE Database
/

CVE-2024-45203

Back to search

CVE-2024-45203

Published: Sep 9, 2024

Modified: Mar 13, 2025

PUBLISHED

Description

Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

VendorProductVersions

istyle Inc.

"@cosme" App for Android

affected
versions prior to 5.69.0

istyle Inc.

"@cosme" App for iOS

affected
versions prior to 6.74.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now