A vulnerability (CVSS 5.3) in KaiOS 3.0 and 3.1 where the /system/kaios/api-daemon binary exposes a local web server on *.localhost with subdomains for each installed application, allowing attackers to determine which apps are installed and access their manifest.webmanifest contents.