Description
The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website via a crafted Intent.
Published: 2026-10-08
Score: 4.6 Medium
EPSS: n/a
KEV: No
Impact: Intent-based redirection to arbitrary URLs
Action: Patch
AI Analysis

Impact

The Android application "Ticket Ryutsu Center" fails to properly validate inputs supplied through its custom URL scheme. This flaw allows a malicious application to craft an Android Intent that causes the victim device to load an arbitrary website without user consent. The primary consequence is that a user may be redirected to a malicious site, potentially exposing them to phishing, malware downloads, or other social‑engineering attacks. The weakness is a classic case of improper input validation (CWE‑939).

Affected Systems

The vulnerability is present in the Ticket Ryutsu Center application distributed by Wavedash Co., Ltd. No specific version information was provided, so all releases of this app should be considered potentially affected until a vendor‑issued fix is released.

Risk and Exploitability

The CVSS score of 4.6 indicates a medium severity, and there is no EPSS data or KEV listing to suggest current exploitation activity. The likely attack vector is a local malicious app that sends a crafted Intent to the application; thus it requires the victim to have an untrusted app installed and the target app to be running or invoked. While the threat level is moderate, the absence of remote or network exploitation keeps the overall risk lower than classic remote code execution flaws.

Generated by OpenCVE AI on October 8, 2026 at 04:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Ticket Ryutsu Center to the latest version that validates custom URL scheme inputs.
  • If the latest update is unavailable, uninstall the application to eliminate the vulnerability.
  • Avoid installing unknown or untrusted applications that could craft malicious Intents, and review installed apps for suspicious intent‑related permissions.

Generated by OpenCVE AI on October 8, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Title Improper custom URL scheme handling enabling arbitrary website access via crafted Intent

Thu, 08 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Description The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website via a crafted Intent.
Weaknesses CWE-939
References
Metrics cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-10-08T02:54:38.873Z

Reserved: 2026-09-17T06:02:21.902Z

Link: CVE-2026-92862

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T03:16:37.683

Modified: 2026-10-08T03:16:37.683

Link: CVE-2026-92862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T04:30:13Z

Weaknesses
  • CWE-939

    Improper Authorization in Handler for Custom URL Scheme