CyberRota Analysis
AI-GeneratedThe vulnerability affects the Evernote and Google Keep note importers in Standard Notes for Android, allowing attackers to execute arbitrary JavaScript by importing specially crafted .enex or HTML files. This can lead to the theft of sensitive encryption keys and note data, as well as unauthorized access to native device APIs. Developers and security teams managing applications that utilize these importers should prioritize addressing this issue to protect user data and maintain application integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.