AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-41918

MEDIUM · CVSS 6.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-08-29 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It affects Android.

CVE
CVE-2024-41918
Severity
MEDIUM
CVSS
6.1
EPSS
0.30%
Android

Original NVD Description

'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application installed on the user's device. As a result, the user may be redirected to an unauthorized site, and the user may become a victim of a phishing attack.

Related CVEs

Other vulnerabilities affecting the same vendor(s)