<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>AusweisApp2 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ausweisapp2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 13:05:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ausweisapp2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cross-Site Scripting Vulnerability in Governikus AusweisApp2</title><link>https://feed.craftedsignal.io/briefs/2026-09-governikus-xss/</link><pubDate>Tue, 15 Sep 2026 13:05:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-governikus-xss/</guid><description>A vulnerability in the Governikus AusweisApp2 software allows a remote, unauthenticated attacker to execute a Cross-Site Scripting (XSS) attack.</description><content:encoded><![CDATA[<p>A Cross-Site Scripting (XSS) vulnerability exists in the Governikus AusweisApp2 software, allowing a remote, unauthenticated attacker to inject and execute malicious scripts. XSS attacks generally target the client-side session of a user by injecting scripts into a trusted application's context. This vulnerability potentially allows an attacker to steal session cookies, capture user input, or perform actions on behalf of the authenticated user within the AusweisApp2 interface. The risk is considered low, but users are advised to monitor for updates from Governikus to address this security flaw.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation could allow unauthorized script execution within the context of the AusweisApp2 application on a victim's machine. This may lead to the compromise of user-specific data managed by the application or unauthorized interaction with the identity services the software facilitates. No specific victim statistics or active exploitation reports are provided in the source documentation.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Monitor official Governikus update channels for patches addressing this XSS vulnerability in AusweisApp2.</li>
<li>Ensure the application is updated to the latest available version once a fix is released.</li>
<li>Restrict execution of untrusted external content or links while the application is active if possible.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">threat</category><category>web-vulnerability</category><category>xss</category></item></channel></rss>