CVE-2026-84431: AirAsia MOVE App com.airasia.mobile com.airasia.core.utils.RealPathUtil.getRealPath path traversal
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument displayname results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
Exploitation requires local access and manipulation of the _display_name argument supplied to com.airasia.core.utils.RealPathUtil.getRealPath. No user interaction is required according to the reported vector.
Which installations should be assessed?
The reported affected scope is the Android AirAsia MOVE App through version 12.47.1. The available information does not identify a fixed version or configuration-based workaround.
Is exploit code available?
Yes. The exploit is reported as public, which may increase the likelihood of attempted exploitation where an attacker has the required local access.