Impact
The Android application contains an improper access control flaw in its in‑app WebView component. Because the WebView does not enforce proper page, it can leak application data or redirect the user to unintended websites. An attacker who can influence the URL loaded by the WebView could cause confidential information to be exposed or force the user to visit a malicious site.
Affected Systems
The vulnerability affects the YAMAP – Social Trekking GPS App for Android developed by YAMAP INC. All presently released versions of the app are potentially impacted until a vendor‑issued patch is applied.
Risk and Exploitability
The CVSS score of 5.1 classifies the weakness as moderate. The EPSS score is less than 1%, indicating a very low but typical behavior, the likely attack vector is to manipulate the URL loaded into the WebView, as opening or interacting with the in-app browser can trigger the flaw. Successful exploitation results in information disclosure and possible redirect to malicious domains, but it does not provide remote code execution or system-wide compromise.
OpenCVE Enrichment