Improper authorization in handler for custom URL scheme issue in @cosme App for Android versions prior 5.69.0 and @cosme App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
@cosme | Istyle | * | 5.69.0 (excluding) |
@cosme | Istyle | * | 6.74.0 (including) |