See how osmand compares to other vendors in security performance
A remote attacker can exploit path traversal in the OsmAnd /open-gpx deep link to fetch arbitrary URLs and write attacker-controlled GPX files within the app's scoped storage.
OsmAnd's exported AIDL service automatically authorizes callers, allowing zero-permission applications to steal real-time location data and write or delete files.
A zero-permission application can send privileged intent extras to OsmAnd's exported MapActivity and silently import attacker-controlled OSF settings.
A zero-permission application can send privileged intent extras to OsmAnd's exported MapActivity and silently import attacker-controlled OSF settings.
A remote attacker can exploit path traversal in the OsmAnd /open-gpx deep link to fetch arbitrary URLs and write attacker-controlled GPX files within the app's scoped storage.
OsmAnd's exported AIDL service automatically authorizes callers, allowing zero-permission applications to steal real-time location data and write or delete files.
Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java.