CVE-2024-23388: Mercari
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper authorization in handler for custom URL scheme issue in "Mercari" App for Android prior to version 5.78.0 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
Affected products
- Mercari Mercari: before 5.78.0 (fixed in 5.78.0)
Published 2024-01-26. Last modified 2026-06-17.