Impact
The RoboForm Password Manager Android application accepts Android intents that contain URLs without performing proper validation, user confirmation, or notification. When an intent with a malicious URL is supplied, the app may silently download files to the device. The downloaded content could be malware, leading to potential compromise of device privacy or further exploitation. This flaw represents an irreversible or insecure state change, as documented by CWE-357.
Affected Systems
The affected product is the RoboForm Password Manager Android application provided by Siber Systems, Inc. No specific version information is supplied in the advisory.
Risk and Exploitability
The CVSS score of this vulnerability is 4.6, indicating moderate risk. There is no EPSS data available, and it is not listed in the CISA KEV catalog. Attackers could trigger the flaw by tricking a user into sending a malicious intent or by compromising a legitimate app that can send such intents. While the vulnerability does not grant remote code execution, the silent download capability can facilitate malware infection or data exfiltration if malicious files are retrieved.
OpenCVE Enrichment