Published:2026/08/13  Last Updated:2026/08/13

JVN#00941257
VoiceTra vulnerable to incorrectly specified destination in a communication channel

Overview

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains a vulnerability due to incorrectly specified destination in a communication channel.

Products Affected

  • "VoiceTra(Voice Translator)" for Android versions 9.1.3, 9.2.0
  • "VoiceTra(Voice Translator)" for iOS versions 9.1.3, 9.2.0

Description

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains the following vulnerability.

  • Incorrectly specified destination in a communication channel (CWE-941)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 5.1
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Base Score 5.4
    • CVE-2026-72506

Impact

Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.

Solution

Update the Application
Apply the latest update according to the information provided by the developer.

Vendor Status

Vendor Link
National Institute of Information and Communications Technology (NICT) Multilingual Speech Translation App “VoiceTra”: Updated Version Released and Service Resumed

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

RyotaK of GMO Flatt Security Inc. reported this vulnerability to NICT and coordinated. After the coordination was completed, RyotaK reported the case to JPCERT/CC to notify users of the solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-72506
JVN iPedia JVNDB-2026-000114