CVE-2025-46498
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-46498 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Zalo Official Live Chat application. This issue allows an attacker to submit malicious requests on behalf of an unsuspecting user, potentially leading to unauthorized actions. The vulnerability can be exploited when users visit a specially crafted website. The Zalo Official Live Chat application, from an unknown version through 1.0.0, is reportedly affected by this issue. Users are advised to apply patches or updates as soon as they become available to mitigate the risk of CSRF attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.