CVE-2013-5726
medium
CVSS v3
—
CVSS v2
6.8
VIR risk
6.8
Description
Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
References
- http://blog.binaryfactory.ca/2013/11/cve-2013-5726-tweetbot-for-ios-and-mac-user-disclosureprivacy-issue/
- http://osvdb.org/99256
- http://seclists.org/fulldisclosure/2013/Nov/9
- http://blog.binaryfactory.ca/2013/11/cve-2013-5726-tweetbot-for-ios-and-mac-user-disclosureprivacy-issue/
- http://osvdb.org/99256
- http://seclists.org/fulldisclosure/2013/Nov/9
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.