Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26966 | Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack. |
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN35290164/ |
|
Fri, 05 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google android Ly Corporation Ly Corporation yahoo! Shopping App |
|
| Vendors & Products |
Google
Google android Ly Corporation Ly Corporation yahoo! Shopping App |
|
| Metrics |
ssvc
|
Fri, 05 Sep 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack. | |
| Weaknesses | CWE-939 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-09-05T13:45:13.400Z
Reserved: 2025-08-29T01:43:32.740Z
Link: CVE-2025-41408
Updated: 2025-09-05T13:42:02.048Z
Status : Deferred
Published: 2025-09-05T06:15:30.327
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-41408
No data.
OpenCVE Enrichment
Updated: 2025-09-05T14:01:46Z
EUVD