Published:2025/12/08  Last Updated:2025/12/08

JVNVU#99973778
Android App "Brother iPrint&Scan" improper use of an external cache directory

Overview

Android App "Brother iPrint&Scan" provided by Brother Industries, Ltd. improperly uses an external cache directory.

Products Affected

  • Android App "Brother iPrint&Scan" versions 6.13.7 and earlier

Description

iPrint&Scan provided by Brother Industries, Ltd. contains the following vulnerability.

  • Improper use of an external cache directory (CWE-524)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 4.8
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N Base Score 3.3
    • CVE-2025-64696

Impact

Application-specific files may be accessed from other malicious applications.

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
Brother Industries, Ltd. Vulnerable 2025/12/08 Brother Industries, Ltd. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Johan Francsics reported this vulnerability to BROTHER INDUSTRIES, LTD. and coordinated.
After the coordination, BROTHER INDUSTRIES, LTD. reported this case to JPCERT/CC to notify users of its solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2025-64696
JVN iPedia