CVE-2024-45240
Status: DeferredHigh (7.4)—
The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On Android 12 and later, this is only exploitable by third-party applications.)
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.16%
- Percentile among all scored CVEs: 4
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-45240",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-45240",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-11-05T21:56:30.336512Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.4,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.4
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:tiktok:tiktok:*:*:*:*:*:android:*:*"
],
"vendor": "tiktok",
"product": "tiktok",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "34.5.5",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-08-24T23:15:04.407",
"references": [
{
"url": "https://hackerone.com/reports/2417516",
"source": "cve@mitre.org"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On Android 12 and later, this is only exploitable by third-party applications.)"
},
{
"lang": "es",
"value": "La aplicación TikTok (también conocida como com.zhiliaoapp.musically) anterior a 34.5.5 para Android permite la toma de control de las interfaces JavaScript de Lynxview a través del cruce de enlaces profundos (en el WebView expuesto de la aplicación). (En Android 12 y versiones posteriores, esto solo es aprovechable por aplicaciones de terceros)."
}
],
"lastModified": "2026-06-17T07:53:50.340",
"sourceIdentifier": "cve@mitre.org"
}