CVE-2023-43955: Fedirtsapana Tv Bro

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute arbitrary code, create arbitrary files. and perform arbitrary downloads via JavaScript that uses takeBlobDownloadData.

Affected products

Published 2023-12-27. Last modified 2026-06-17.