CVE-2024-23388: Mercari

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

Affected products

  • Mercari Mercari: before 5.78.0 (fixed in 5.78.0)

Published 2024-01-26. Last modified 2026-06-17.