CVE-2024-9285

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 27, 2025
CWE ID 94
CWE ID 79

Summary

CVE-2024-9285 is a newly disclosed vulnerability affecting the Tu Yafeng Via Browser up to version 5.9.0 on Android. This issue, rated as problematic, is related to the component Javascript Bridge and involves unknown processing. The vulnerability allows for cross-site scripting attacks, which can be initiated remotely. The exploit has been made public, increasing the risk of exploitation. It is strongly advised to install the patch to mitigate this security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share