JVN#00941257
VoiceTra vulnerable to incorrectly specified destination in a communication channel
Overview
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains a vulnerability due to incorrectly specified destination in a communication channel.
Products Affected
- "VoiceTra(Voice Translator)" for Android versions 9.1.3, 9.2.0
- "VoiceTra(Voice Translator)" for iOS versions 9.1.3, 9.2.0
Description
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains the following vulnerability.
- Incorrectly specified destination in a communication channel (CWE-941)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 5.1
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Base Score 5.4
- CVE-2026-72506
Impact
Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
Solution
Update the Application
Apply the latest update according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| National Institute of Information and Communications Technology (NICT) | Multilingual Speech Translation App “VoiceTra”: Updated Version Released and Service Resumed |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
RyotaK of GMO Flatt Security Inc. reported this vulnerability to NICT and coordinated. After the coordination was completed, RyotaK reported the case to JPCERT/CC to notify users of the solution through JVN.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-72506 |
| JVN iPedia |
JVNDB-2026-000114 |