| [Japanese] | |
JVNDB-2026-016626 | |
Android App "RoboForm Password Manager" insufficient validation of Android intents | |
| Overview | |
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. accepts intents from other applications to open relevant web pages (e.g., login pages), but without sufficient URL validation, user confirmation nor notification. | |
| CVSS Severity (What is CVSS?) | |
|
CVSS V3 Severity:
Base Metrics 3.3 (Low) [Other]
| |
| Affected Products | |
|
| |
Siber Systems Inc. | |
iOS App is not affected by the vulnerability. | |
| Impact | |
If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification. | |
| Solution | |
[Update the App] | |
| Vendor Information | |
Siber Systems Inc. | |
| CWE (What is CWE?) | |
|
| |
| CVE (What is CVE?) | |
|
| |
| References | |
| |
| Revision History | |
|
| Date Public | 2026/05/20 |
| Date First Published | 2026/05/21 |
| Date Last Updated | 2026/05/21 |


