CVE-2024-9285
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 27, 2025
CWE ID 94
CWE ID 79
Summary
CVE-2024-9285 is a newly disclosed vulnerability affecting the Tu Yafeng Via Browser up to version 5.9.0 on Android. This issue, rated as problematic, is related to the component Javascript Bridge and involves unknown processing. The vulnerability allows for cross-site scripting attacks, which can be initiated remotely. The exploit has been made public, increasing the risk of exploitation. It is strongly advised to install the patch to mitigate this security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.