jvndb-2026-016626
Vulnerability from jvndb
Published
2026-05-21 17:22
Modified
2026-05-21 17:22
Severity ?
Summary
Android App "RoboForm Password Manager" insufficient validation of Android intents
Details
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. accepts intents from other applications to open relevant web pages (e.g., login pages), but without sufficient URL validation, user confirmation nor notification.<a href='https://cwe.mitre.org/data/definitions/357.html' target='_blank'></a><ul><li>Insufficient UI Warning of Dangerous Operations (CWE-357) - CVE-2026-47782</li><li>The CVSS vectors above assume that a victim user is directed to install some malicious app, and the app sends an intent to make RoboForm to download some files silently</li></ul>Johan Francsics reported this vulnerability to JPCERT/CC. JPCERT/CC coordinated with the developer.
Impacted products
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-016626.html",
  "dc:date": "2026-05-21T17:22+09:00",
  "dcterms:issued": "2026-05-21T17:22+09:00",
  "dcterms:modified": "2026-05-21T17:22+09:00",
  "description": "Android App \"RoboForm Password Manager\" provided by Siber Systems, Inc. accepts intents from other applications to open relevant web pages (e.g., login pages), but without sufficient URL validation, user confirmation nor notification.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/357.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eInsufficient UI Warning of Dangerous Operations (CWE-357) - CVE-2026-47782\u003c/li\u003e\u003cli\u003eThe CVSS vectors above assume that a victim user is directed to install some malicious app, and the app sends an intent to make RoboForm to download some files silently\u003c/li\u003e\u003c/ul\u003eJohan Francsics reported this vulnerability to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
  "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-016626.html",
  "sec:cpe": {
    "#text": "cpe:/a:misc:siber_systems_roboform_password",
    "@product": "RoboForm Password Manager",
    "@vendor": "Siber Systems Inc.",
    "@version": "2.2"
  },
  "sec:cvss": {
    "@score": "3.3",
    "@severity": "Low",
    "@type": "Base",
    "@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
    "@version": "3.0"
  },
  "sec:identifier": "JVNDB-2026-016626",
  "sec:references": [
    {
      "#text": "https://jvn.jp/en/vu/JVNVU93461473/index.html",
      "@id": "JVNVU#93461473",
      "@source": "JVN"
    },
    {
      "#text": "https://www.cve.org/CVERecord?id=CVE-2026-47782",
      "@id": "CVE-2026-47782",
      "@source": "CVE"
    },
    {
      "#text": "https://cwe.mitre.org/data/definitions/357.html",
      "@id": "CWE-357",
      "@title": "Insufficient UI Warning of Dangerous Operations(CWE-357)"
    }
  ],
  "title": "Android App \"RoboForm Password Manager\" insufficient validation of Android intents"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…