CVE-2024-6294
CVSS 3.1 Score 3.9 of 10 (low)
Details
Published Jun 25, 2024
CWE ID 200
Summary
CVE-2024-6294 is a newly disclosed vulnerability affecting the udn News Android App. The app stores user session information in a logcat file upon login. This presents a significant risk as any malicious app or an attacker with physical access to the device can retrieve this session data and subsequently log into the news app and potentially other services provided by udn. This vulnerability could potentially lead to unauthorized access to sensitive user information. Users are strongly advised to update their apps to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- News App