CVE-2019-6024: Rakuten Rakuma

Medium severity, CVSS 6.5. EPSS: 2% chance of exploitation in the next 30 days.

Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass authentication and obtain the user's authentication information via a malicious application created by the third party.

Affected products

  • Rakuten Rakuma: up to and including 7.15.0; up to and including 7.16.4

Published 2019-12-26. Last modified 2026-06-17.