node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon