CVE-2026-47782 PUBLISHED

Assigner: jpcert
Reserved: 20.05.2026 Published: 20.05.2026 Updated: 21.05.2026

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.6

Product Status

Vendor Siber Systems, Inc.
Product Android App "RoboForm Password Manager"
Versions
  • Version 9.8.6.3 and prior is affected

References

Problem Types