Impact
The Android application "Ticket Ryutsu Center" fails to properly validate inputs supplied through its custom URL scheme. This flaw allows a malicious application to craft an Android Intent that causes the victim device to load an arbitrary website without user consent. The primary consequence is that a user may be redirected to a malicious site, potentially exposing them to phishing, malware downloads, or other social‑engineering attacks. The weakness is a classic case of improper input validation (CWE‑939).
Affected Systems
The vulnerability is present in the Ticket Ryutsu Center application distributed by Wavedash Co., Ltd. No specific version information was provided, so all releases of this app should be considered potentially affected until a vendor‑issued fix is released.
Risk and Exploitability
The CVSS score of 4.6 indicates a medium severity, and there is no EPSS data or KEV listing to suggest current exploitation activity. The likely attack vector is a local malicious app that sends a crafted Intent to the application; thus it requires the victim to have an untrusted app installed and the target app to be running or invoked. While the threat level is moderate, the absence of remote or network exploitation keeps the overall risk lower than classic remote code execution flaws.
OpenCVE Enrichment