Impact
VoiceTra, the voice translation application distributed by the National Institute of Information and Communications Technology, has a flaw that allows an attacker to specify an incorrect destination in a communication channel. This misdirection can cause users to connect to a server or service chosen by the attacker, which may result in the theft of input data or the display of misleading translation results. The vulnerability is categorized as CWE‑941, indicating possible information exposure.
Affected Systems
The issue affects all users of VoiceTra for Android and VoiceTra for iOS. No specific affected versions are listed, so any currently installed build may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.1 places this vulnerability in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Given the nature of the flaw, an attacker would need to be able to influence the communication path—likely through knowledge of the app’s network configuration or by hosting a malicious server that the app could be directed to. The likelihood of exploitation remains uncertain, but the potential for data compromise warrants prompt attention.
OpenCVE Enrichment