CVE-2023-29749
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jun 9, 2023
Updated: Jan 6, 2025
Summary
CVE-2023-29749 is a newly identified privilege escalation vulnerability that affects Yandex Navigator version 6.60 for Android. Malicious apps can exploit this issue by manipulating the SharedPreference files in Yandex Navigator, resulting in unauthorized escalation of privileges. This vulnerability could potentially allow attackers to gain elevated access to the system, leading to serious security implications for affected devices. Users are advised to update their Yandex Navigator app as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Yandex Navigator
Affected Vendors
- Yandex