Information from Newphoria Corporation
Title:MEGAPHONE MUSIC vulnerable to URL whitelist bypass
This is a statement from the vendor itself with no modification by JPCERT/CC.
Vulnerability in access restriction of MEGAPHONE MUSIC has been found.
iOS and Android MEGAPHONE MUSIC up to version 1.0
MEGAPHONE MUSIC could be loaded using URL scheme with the possibility to open an arbitrary page.
In Android application it is possible to call API's on behalf of the affected application.
In iOS application it is possible to execute optional API's used by the iOS application.
Update the application to the latest version.
Update to version 1.1 from GooglePlay.
Update to version 1.1 from AppStore.
This vulnerability report was sent according to Information Security Early Warning partnership within regulation between our company and IPA with JPCERT/CC.
The information regarding the vulnerability was reported to us by Sprout Inc.
Our special thanks to Kenta Suefusa and Tomonori Shiomi of Sprout Inc., and also to anyone involved into Information Security Early Warning partnership.