CVE-2023-49001: Indibrowser Indi Browser

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue in Indi Browser (aka kvbrowser) v.12.11.23 allows an attacker to bypass intended access restrictions via interaction with the com.example.gurry.kvbrowswer.webview component.

Affected products

Published 2023-12-27. Last modified 2026-06-17.