Impact
The vulnerability resides in Reader Tools PDF Reader App 98.8 for Android and is triggered by the ActSplashNew.handleDeeplink function. Manipulating the _display_name argument allows an attacker to traverse the file system path and read arbitrary local files. The impact is restricted to local file disclosure; there is no remote code execution or privilege escalation reported.
Affected Systems
The affected system is Reader Tools PDF Reader App version 98.8 running on Android devices. No other variants or versions are mentioned.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local attack vector; the attacker must trigger a deeplink with a crafted _display_name argument. The exploit has been publicly disclosed and may be used, but no evidence of active exploitation is provided. The vendor did not respond to the disclosure.
OpenCVE Enrichment