CVE-2026-65995: GHSL-2026-109: Local apps can steal location data and write files through OsmAnd - CVE-2026-65995
Published Oct 1, 2026
·Updated
OsmAnd's exported AIDL service automatically authorizes callers, allowing zero-permission applications to steal real-time location data and write or delete files.
Affected Software
1 affected component
Osmand Osmand
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker needs to run an application locally on the device. The application does not need any Android permissions because the exported AIDL service automatically authorizes callers.