The Home Assistant Companion for Android app up to version 2023.8.2 contains a vulnerability where arbitrary URLs can be loaded in a WebView component. This flaw allows attackers to direct the WebView to malicious sites, enabling attacks such as arbitrary JavaScript execution, limited native code execution, and credential theft. The vulnerability is tracked as GHSL-2023-142 and has been patched in version 2023.9.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Android lab that reproduces the exploitation pattern behind CVE-2023-41898 (Home Assistant Companion for Android unvalidated deep link handling) in a reduced educational form. It is not a scanner; it contains working exploit components and a vulnerable target app. Structure: the repo has two Android applications and two web payload pages. `victim/` implements the vulnerable flow: `MyActivity.java` is an exported deep-link entry point that accepts an ACTION_VIEW intent and directly loads the supplied URI into a JavaScript-enabled WebView after only appending `mobile=1`. Its WebViewClient also recognizes the custom scheme prefix `homeassistant://navigate/` and forwards the remainder into `WebViewActivity`. `WebViewActivity.java` is the second-stage privileged WebView; if the supplied `path` starts with `http://` or `https://`, it loads that absolute URL without trust validation and exposes a JavaScript interface named `externalApp`. That bridge's `getExternalAuth()` method returns a synthetic token (`LAB_TOKEN_CVE_2023_41898_NOT_REAL`) to page JavaScript via `evaluateJavascript`. The `attacker/` app is the launcher for exploitation. `attacker/MainActivity.java` builds an explicit intent targeting `lab.cve202341898.victim.MyActivity` and sets attacker-controlled data, defaulting to `http://10.0.2.2:8000/exploit.html`. Because the intent is explicit, the victim's manifest deep-link filter for `https://my.home-assistant.io/redirect/` does not protect against this path. The `web/` directory contains the staged payload. `exploit.html` is the first-stage page loaded by the victim's initial WebView; after a short delay it redirects to `homeassistant://navigate/http://10.0.2.2:8000/second-stage.html`. This triggers the victim's internal navigation handler and opens `second-stage.html` inside the privileged WebView. `second-stage.html` then calls `window.externalApp.getExternalAuth(...)` and displays the returned token, demonstrating attacker-controlled JavaScript execution in a more privileged context. Overall exploit capability: local app-to-app trigger plus web content delivery leading to arbitrary attacker HTML/JavaScript execution in victim WebViews and abuse of an exposed JavaScript bridge to retrieve sensitive data. The lab uses only synthetic data and localhost-style emulator networking (`10.0.2.2:8000`), but the exploit chain clearly models a real-world deep-link-to-WebView pivot.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.