CVE-2018-16179: Mizuhobank Mizuho Direct Application

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

The Mizuho Direct App for Android version 3.13.0 and earlier does not verify server certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Affected products

  • Mizuhobank Mizuho Direct Application: up to and including 3.13.0

Published 2019-01-09. Last modified 2026-06-17.