Security Advisory

CVE-2021-20835

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-11-24 08:25:38
Last updated 2024-08-03 17:53:23
Assigner jpcert
CVSS score not scored
State PUBLISHED

Description

Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches an arbitrary Activity of the app via the vulnerable App, which may result in Mercari account's access token being obtained.