Improper Verification of Source of a Communication Channel in YAMAP -Social Trekking GPS App - CVE-2026-85125
Published: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access control vulnerability related to its WebView implementation. A remote attacker can cause the in-app browser to leak information from the app or redirect users to unintended websites.