|
[Japanese]
|
JVNDB-2026-000131
|
"YAMAP -Social Trekking GPS App" vulnerable to improper access control
|
Android application "YAMAP -Social Trekking GPS App" provided by YAMAP INC. contains the following vulnerability:- Improper Verification of Source of a Communication Channel (CWE-940) - CVE-2026-85125
Koki Sato of BroadBand Security, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 5.4 (Medium) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
|
CVSS v4 Severity
Base Metrics: 5.1 (Medium) [IPA Score]
- Access Vector (AV): Network
- Attack Complexity (AC): Low
- Attack Requirements (AT): None
- Privileges Required (PR): None
- User Interaction (UI): Active
Vulnerable System Impact
- Confidentiality Impact (VC): Low
- Integrity Impact (VI): Low
- Availability Impact (VA): None
Subsequent System Impact
- Confidentiality Impact (SC): None
- Integrity Impact (SI): None
- Availability Impact (SA): None
|
|
YAMAP INC.
- Android application "YAMAP -Social Trekking GPS App" versions v17.1.0 and earlier
|
|
The in-app browser may cause information leakage from the app or redirect users to unintended websites.
|
[Update the Application]
Update the application to the latest version according to the information provided by the developer.
|
YAMAP INC.
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2026-85125
|
- JVN : JVN#69877538
|
- [2026/09/14]
Web page was published
|