Improper Authorization in Handler for Custom URL Scheme in Rakuten Ichiba App for Android and Rakuten Ichiba App for iOS - CVE-2024-41918
Published: August 21, 2024
Vulnerability identifier: #VU96315
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41918
CWE-ID: CWE-939
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not restrict access to the function to access a requested URL using Custom URL Scheme properly. A remote attacker can trick a victim to access an arbitrary website via the vulnerable App.
Affected software
Rakuten Ichiba App for Android
Rakuten Ichiba App for iOS
Rakuten Ichiba App for iOS
How to mitigate CVE-2024-41918
Install updates from vendor's website.