CVE-2018-0691: Kddi + Message
Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.
Multiple +Message Apps (Softbank +Message App for Android prior to version 10.1.7, Softbank +Message App for iOS prior to version 1.1.23, NTT DOCOMO +Message App for Android prior to version 42.40.2800, NTT DOCOMO +Message App for iOS prior to version 1.1.23, KDDI +Message App for Android prior to version 1.0.6, and KDDI +Message App for iOS prior to version 1.1.23) do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected products
- Kddi + Message: before 1.0.6 (fixed in 1.0.6); before 1.1.23 (fixed in 1.1.23)
- Ntt Tocomo + Message: before 1.1.23 (fixed in 1.1.23)
- Ntttocomo + Message: before 42.40.2800 (fixed in 42.40.2800)
- Softbank + Message: before 10.1.7 (fixed in 10.1.7); before 1.1.23 (fixed in 1.1.23)
Published 2018-11-15. Last modified 2026-06-17.