CVE-2023-33244: Obsidian
High severity, CVSS 8.2. EPSS: 0.5% chance of exploitation in the next 30 days.
Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.
Affected products
- Obsidian Obsidian: before 1.2.2 (fixed in 1.2.2)
Published 2023-05-20. Last modified 2026-06-17.