Impact
The vulnerability arises from the getExternalCacheDir function in iAI Lab PDF AI App, which allows a path traversal by manipulating the _display_name argument. This flaw can enable an attacker with local device access to read or write arbitrary files within the external cache directory, potentially compromising personal data, configuration files, or other sensitive information stored on the device. The weakness is classified as CWE-22 and is limited to affecting confidentiality and integrity of local files rather than remote systems.
Affected Systems
The flaw affects iAI Lab PDF AI App version 4.21.0 running on Android devices. No other product versions are listed as impacted. Users of this specific version are the only ones at risk.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity level, and the exploit requires a local approach, meaning the attacker must have physical or credential access to the device. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying that it is not widely known as a actively exploited threat at this time. However, since the exploit code has been released publicly, it could be used by malicious actors who gain local access to compromise data integrity on the device. The absence of a public remote exploit reduces the threat surface, but local attackers could still abuse the path traversal for data exfiltration or manipulation.
OpenCVE Enrichment