Description
A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipulation of the argument _display_name leads to path traversal. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Reader Tools PDF Reader App 98.8 for Android and is triggered by the ActSplashNew.handleDeeplink function. Manipulating the _display_name argument allows an attacker to traverse the file system path and read arbitrary local files. The impact is restricted to local file disclosure; there is no remote code execution or privilege escalation reported.

Affected Systems

The affected system is Reader Tools PDF Reader App version 98.8 running on Android devices. No other variants or versions are mentioned.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local attack vector; the attacker must trigger a deeplink with a crafted _display_name argument. The exploit has been publicly disclosed and may be used, but no evidence of active exploitation is provided. The vendor did not respond to the disclosure.

Generated by OpenCVE AI on September 3, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the device is running Reader Tools PDF Reader App 98.8 and inspect vendor release notes for a security update that addresses the path traversal.
  • If a patched version is available, install it immediately.
  • If an update is unavailable, disable or remove the deeplink feature that calls ActSplashNew.handleDeeplink, if the application allows such configuration.
  • Limit the application’s file system permissions or run the app in a sandboxed environment to prevent local file disclosure.

Generated by OpenCVE AI on September 3, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipulation of the argument _display_name leads to path traversal. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Reader Tools PDF Reader App File ActSplashNew.handleDeeplink path traversal
First Time appeared Reader Tools
Reader Tools pdf Reader App
Weaknesses CWE-22
CPEs cpe:2.3:a:reader_tools:pdf_reader_app:*:*:*:*:*:*:*:*
Vendors & Products Reader Tools
Reader Tools pdf Reader App
References
Metrics cvssV2_0

{'score': 3.2, 'vector': 'AV:L/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Reader Tools Pdf Reader App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-02T19:40:27.809Z

Reserved: 2026-09-02T13:10:15.968Z

Link: CVE-2026-84852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T20:17:42.050

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-84852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:30:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')