CVE-2026-85125
Received Received - Intake

Improper Access Control in YAMAP Social Trekking GPS App

Vulnerability report for CVE-2026-85125, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: JPCERT/CC

Description

The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-940 The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control flaw in the Android app YAMAP's WebView implementation. It allows the in-app browser to leak information from the app or redirect users to unintended websites due to insufficient verification of external inputs and unnecessary permission activation.

Detection Guidance

This vulnerability is specific to the YAMAP app's WebView implementation. Detection involves checking the installed app version on your Android device. Compare the version against v17.1.0 or earlier. If your version is v17.1.0 or older, the device is vulnerable.

Impact Analysis

The vulnerability could expose your app data or redirect you to malicious sites. However, no confirmed cases of data exfiltration or attacks have been reported. Updating to version 17.2.0 or later mitigates this risk.

Mitigation Strategies

Update the YAMAP app to version v17.2.0 or later via Google Play Store. This version includes the fix for the improper access control vulnerability in the WebView implementation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85125. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart