Security Advisory

CVE-2021-20835

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-11-24 08:25:38
Last updated 2024-08-03 17:53:23
Assigner jpcert
State PUBLISHED

Description

Improper authorization in handler for custom URL scheme vulnerability in Android App Mercari (Merpay) - Marketplace and Mobile Payments App (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches an arbitrary Activity of the app via the vulnerable App, which may result in Mercari accounts access token being obtained.