CVE-2026-85125: Medium severity vulnerability
The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites.
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is remotely reachable and requires no attacker privileges, but it requires user interaction. A user would need to interact with content that causes the app's in-app WebView to be used.
Who is exposed to the reported impact?
Users of the YAMAP Android application who use its in-app browser are the relevant exposure group. The reported impacts are information leakage from the app and redirection to unintended websites.
Does the available information confirm whether default installations are affected?
No. The provided information identifies the WebView implementation as affected but does not state whether the vulnerable behavior is enabled or reachable in a default installation.