CVE-2026-65997: GHSL-2026-108: Local apps can silently import malicious settings into OsmAnd - CVE-2026-65997
Published Oct 1, 2026
·Updated
A zero-permission application can send privileged intent extras to OsmAnd's exported MapActivity and silently import attacker-controlled OSF settings.
Affected Software
1 affected component
Osmand Osmand
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
Does exploitation require the attacker to obtain any Android permissions?
No. A zero-permission application can send the relevant intent extras to OsmAnd's exported MapActivity.
2
Does the victim need to approve or interact with the imported settings?
No. The settings import can occur silently.