# CVE-2024-52887 - Self-XSS vulnerability in Mobile Access Native Applications 'favorites' dialog

Please read this important update from Check Point.

## Security Alert:

- **Level:** Low
- **Product:** Mobile Access / SSL VPN
- **Version:** R81.10 (EOS), R81.20, R82
- **OS:** Gaia
- **Last Modified:** 2025-04-27

## Symptoms

- The Mobile Access portal is vulnerable to a stored, self-XSS attack.

An authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

So far today, no attack with actual impact is known.

- This issue received the ID [CVE-2024-52887](https://www.cve.org/CVERecord?id=CVE-2024-52887)

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 14
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 99
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 173

## Article Properties

- **Access Level:** General
- **Severity:** Low
- **Status:** Approved
- **Date Created:** 2025-01-29
- **Last Modified:** 2025-04-27
