An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing opened conversation by sending an intent.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/siacs/Conversations/commit/7177c523a1b31988666b9337249a4f1d0c36f479 | third party advisory patch |