Description
The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The Android application contains an improper access control flaw in its in‑app WebView component. Because the WebView does not enforce proper page, it can leak application data or redirect the user to unintended websites. An attacker who can influence the URL loaded by the WebView could cause confidential information to be exposed or force the user to visit a malicious site.

Affected Systems

The vulnerability affects the YAMAP – Social Trekking GPS App for Android developed by YAMAP INC. All presently released versions of the app are potentially impacted until a vendor‑issued patch is applied.

Risk and Exploitability

The CVSS score of 5.1 classifies the weakness as moderate. The EPSS score is less than 1%, indicating a very low but typical behavior, the likely attack vector is to manipulate the URL loaded into the WebView, as opening or interacting with the in-app browser can trigger the flaw. Successful exploitation results in information disclosure and possible redirect to malicious domains, but it does not provide remote code execution or system-wide compromise.

Generated by OpenCVE AI on September 15, 2026 at 14:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s security update for YAMAP as soon as it becomes available to fix the WebView access control issue.
  • If an update is not yet released, configure the app so that the WebView will only load content from approved trusted domains, effectively whitelisting allowed URLs.
  • Advise users to avoid entering sensitive personal data while using the app or clicking unknown or suspicious links within the app.

Generated by OpenCVE AI on September 15, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Yamap
Yamap yamap
Vendors & Products Yamap
Yamap yamap

Tue, 15 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title WebView Improper Access Control Allows Information Leakage and Redirects in YAMAP App

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in WebView Leading to Information Leakage and Unintended Redirects

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in WebView Leading to Information Leakage and Unintended Redirects

Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites.
Weaknesses CWE-940
References
Metrics cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-14T19:35:41.742Z

Reserved: 2026-09-03T08:26:09.640Z

Link: CVE-2026-85125

cve-icon Vulnrichment

Updated: 2026-09-14T19:35:37.939Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:22.037

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-85125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:32Z

Weaknesses
  • CWE-940

    Improper Verification of Source of a Communication Channel