# CVE-2025-41408

## Summary

- **CVE ID:** CVE-2025-41408
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-939
- **Published:** Sep 5, 2025
- **Last Modified:** Mar 12, 2026

## Description

Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack.

## Affected Products

- LY Corporation — "Yahoo! Shopping" App for Android (versions prior to 14.15.0)

## References

- [CNA](https://jvn.jp/en/jp/JVN35290164/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 19.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._