In brief, he found that a potential attacker could include a malicious payload into an SSID name. Then, if a Windows device running Avast antivirus would connect to this network, the antivirus would execute the XSS.
The exploit basically worked due to a feature in the Avast antivirus program for Windows. By default, the program displayed a pop-up notification whenever the device attempts to connect to a WiFi network. As it used to display the SSID name without sanitization, it was possible for any potential attacker to inject a malicious payload into the SSID name, which would then execute.
Following the script execution, the pop-up notification would then display a fake login prompt created by the attacker. Since the targeted user would see no URL, the victim would be more likely to believe it safe to enter their login credentials.
For further clarification, the researcher demonstrated the attack in the following video.
Subsequently, Avast awarded a bounty of $5000 to the researcher!
The vulnerability not only affected Avast but also AVG. So, the flaws have received CVE numbers CVE-2019-18653 for Avast, and CVE-2019-18654 for AVG.
Furthermore, the firm also fixed the vulnerability with the release of Avast 19.4.
Recently, we have also reported about a privilege escalation vulnerability in Bitdefender Antivirus Free 2020, and Comodo Antivirus. Whereas the Android Antivirus apps are also no exception to such vulnerabilities.