Impact
The vulnerability is an improper access control in a component of the ManabiPocket for Parents Android app. An attacker can craft an Intent targeting that component, which the app accepts without validating the caller, allowing a malicious third‑party app to retrieve sensitive data that should be protected. This weakness corresponds to CWE‑926. The impact is that personal or parental data stored or displayed by the app could be accessed by an attacker.
Affected Systems
The affected product is the ManabiPocket for Parents application from NTT DOCOMO BUSINESS, Inc. for Android devices. All releases that contain the vulnerable component are potentially affected until a vendor patch is released. No specific version details are available, and the CNA did not publish an affected‑version list.
Risk and Exploitability
The CVSS score of 1.8 indicates a low overall severity. The EPSS score of <1% shows a very low likelihood that this vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to have an Android device with the vulnerable app installed and to install a malicious app that can target the component via an Intent. If such conditions exist, the attacker could read sensitive data through the exposed component.
OpenCVE Enrichment