Description
A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The manipulation leads to path traversal. An attack has to be approached locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path‑traversal flaw exists in the getDataColumn function of the ExpoShareIntentModule.kt file within the com.mapquest.android.ace component of MapQuest Get Directions App version 10.16.1 on Android. The flaw allows an attacker who can trigger the function locally to construct file paths that escape the intended directory, enabling the reading of arbitrary files on the device. This could expose confidential data stored on the phone and provide a foothold for further local privilege escalation or malware execution. The vulnerability is classified as a medium severity issue with a CVSS score of 4.8 and is explicitly described as a local attack scenario. No remote exploitation vector is disclosed, but the exploit is publicly available.

Affected Systems

The affected product is MapQuest Get Directions App, version 10.16.1, running on Android devices. No additional versions or operating systems are listed as impacted, so the risk is confined to this specific build of the application.

Risk and Exploitability

The CVSS score indicates moderate risk, and the lack of an EPSS rating means there is no current data on exploitation probability. Because the issue requires local access and the attacker must be able to invoke the vulnerable function on the device, the threat is limited to scenarios where the device is compromised or the user interacts with a malicious intent. The vulnerability is not listed in the CISA KEV catalog, but the public availability of an exploit suggests that the risk to users of the affected app build should be treated as significant until a vendor patch or mitigation is applied.

Generated by OpenCVE AI on September 2, 2026 at 03:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MapQuest Get Directions App to the latest version once a vendor patch is released.
  • Restrict the app’s file‑system access by configuring device or MDM policies to limit its ability to read sensitive directories.
  • Disable or secure the app’s intent handling for file sharing if the feature is unnecessary for users.

Generated by OpenCVE AI on September 2, 2026 at 03:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The manipulation leads to path traversal. An attack has to be approached locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title MapQuest Get Directions App com.mapquest.android.ace ExpoShareIntentModule.kt getDataColumn path traversal
First Time appeared Mapquest
Mapquest get Directions App
Weaknesses CWE-22
CPEs cpe:2.3:a:mapquest:get_directions_app:*:*:*:*:*:*:*:*
Vendors & Products Mapquest
Mapquest get Directions App
References
Metrics cvssV2_0

{'score': 3.2, 'vector': 'AV:L/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mapquest Get Directions App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-02T02:30:10.468Z

Reserved: 2026-09-01T19:48:20.733Z

Link: CVE-2026-84442

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T03:16:48.173

Modified: 2026-09-02T03:16:48.173

Link: CVE-2026-84442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T03:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')