Kaiostech develops a mobile operating system targeting feature phones and entry-level devices, and its vulnerability exposure concentrates in this narrow but strategically important product line. The durable signal centers on web-interaction and command-handling weakness classes—including cross-site scripting, command injection, and resource-exposure issues—that reflect the browser and system-integration surface of a mobile platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaiostech over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33294CRITICAL An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port 2929. The server acc | May 22, 2023 | 9.8 | 30 | NO | NO |
CVE-2019-7386MEDIUM A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the int | Mar 21, 2019 | 6.5 | 23 | NO | NO |
CVE-2019-14757MEDIUM An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to | Sep 14, 2020 | 6.1 | 22 | NO | NO |
CVE-2019-14758MEDIUM An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via e | Sep 14, 2020 | 6.1 | 21 | NO | NO |
CVE-2019-14756MEDIUM An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a speciall | Sep 14, 2020 | 6.1 | 21 | NO | NO |
CVE-2023-27108MEDIUM An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns the user's call log without origin or permission checks. An a | May 1, 2023 | 5.3 | 19 | NO | NO |
CVE-2023-33293MEDIUM An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., m | May 22, 2023 | 5.3 | 18 | NO | NO |
CVE-2019-14761MEDIUM An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the | Sep 14, 2020 | 4.4 | 18 | NO | NO |
CVE-2019-14760MEDIUM An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into | Sep 14, 2020 | 4.4 | 18 | NO | NO |
CVE-2019-14759MEDIUM An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitr | Sep 14, 2020 | 4.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaiostech.
Media articles that mention a CVE ID that affects a product developed by Kaiostech — matched by CVE ID, not by vendor name.