GHSL-2026-109: Local apps can steal location data and write files through OsmAnd - CVE-2026-65995
Published Oct 1, 2026
·Updated
OsmAnd's exported AIDL service automatically authorizes callers, allowing zero-permission applications to steal real-time location data and write or delete files.
Affected Software
1 affected component
Osmand Osmand
Event History
Oct 1, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
A local application on the same device can exploit it with no permissions. The affected exported AIDL service automatically authorizes callers.
2
What could a malicious application do through the exposed service?
It can obtain real-time location data and write or delete files.