CVE-2026-47782
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-357
- Published
- 2026-05-20
- Last modified
- 2026-05-21
Affected products
- Siber Systems, Inc. Android App "RoboForm Password Manager"
Weakness type
Related vulnerabilities
- CVE-2026-58597 — Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-26151 — Remote Desktop Spoofing Vulnerability
- CVE-2025-47967 — Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
- CVE-2025-33054 — Remote Desktop Spoofing Vulnerability
- CVE-2025-49587 — XWiki does not require right warnings for notification displayer objects
- CVE-2025-49585 — XWiki does not require right warnings for XClass definitions
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
- CVE-2025-49582 — XWiki's required right warnings for macros are incomplete