Impact
A path‑traversal flaw exists in the getDataColumn function of the ExpoShareIntentModule.kt file within the com.mapquest.android.ace component of MapQuest Get Directions App version 10.16.1 on Android. The flaw allows an attacker who can trigger the function locally to construct file paths that escape the intended directory, enabling the reading of arbitrary files on the device. This could expose confidential data stored on the phone and provide a foothold for further local privilege escalation or malware execution. The vulnerability is classified as a medium severity issue with a CVSS score of 4.8 and is explicitly described as a local attack scenario. No remote exploitation vector is disclosed, but the exploit is publicly available.
Affected Systems
The affected product is MapQuest Get Directions App, version 10.16.1, running on Android devices. No additional versions or operating systems are listed as impacted, so the risk is confined to this specific build of the application.
Risk and Exploitability
The CVSS score indicates moderate risk, and the lack of an EPSS rating means there is no current data on exploitation probability. Because the issue requires local access and the attacker must be able to invoke the vulnerable function on the device, the threat is limited to scenarios where the device is compromised or the user interacts with a malicious intent. The vulnerability is not listed in the CISA KEV catalog, but the public availability of an exploit suggests that the risk to users of the affected app build should be treated as significant until a vendor patch or mitigation is applied.
OpenCVE Enrichment