CVE-2024-45240

The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On Android 12 and later, this is only exploitable by third-party applications.)
References
Configurations

No configuration.

History

No history.

Information

Published : 2024-08-24 23:15

Updated : 2026-06-17 07:53


NVD link : CVE-2024-45240

Mitre link : CVE-2024-45240

CVE.ORG link : CVE-2024-45240


JSON object : View

Products Affected

No product.

CWE

No CWE.