Impact
A vulnerability in the t5.l.c function of ZomboDroid Meme Generator App 4.6830 allows local path traversal, meaning an attacker with local device access can manipulate file paths to read or potentially overwrite files outside the intended directory. The weakness is a classic directory traversal flaw (CWE‑22). Because the exploit requires the attacker to be on the device, it does not enable remote compromise, but it can expose sensitive local data.
Affected Systems
The affected product is the ZomboDroid Meme Generator App 4.6830 for Android, specifically the component com.zombodroid.MemeGenerator’s t5.l.c function.
Risk and Exploitability
The CVSS base score of 4.8 indicates a moderate impact with local scope; the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Local access to the device is required, so the attack vector is limited to a user who has physically or remotely gained local privileges on the victim’s Android device. The vulnerability has been publicly disclosed, indicating that potential attackers could attempt path traversal once an affected device is located.
OpenCVE Enrichment