Published:2026/09/14 Last Updated:2026/09/14
JVN#69877538
"YAMAP -Social Trekking GPS App" vulnerable to improper access control
Overview
Android application "YAMAP -Social Trekking GPS App" provided by YAMAP INC. contains an improper access control vulnerability related to its WebView implementation.
Products Affected
- Android application "YAMAP -Social Trekking GPS App" versions v17.1.0 and earlier
Description
Android application "YAMAP -Social Trekking GPS App" provided by YAMAP INC. contains the following vulnerability:
- Improper Verification of Source of a Communication Channel (CWE-940)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 5.1
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Base Score 5.4
- CVE-2026-85125
Impact
The in-app browser may cause information leakage from the app or redirect users to unintended websites.
Solution
Update the Application
Update the application to the latest version according to the information provided by the developer.
Vendor Status
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Koki Sato of BroadBand Security, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-85125 |
| JVN iPedia |
JVNDB-2026-000131 |