CVE-2025-41408: Ly Corporation Yahoo! Shopping App For Android

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack.

Affected products

  • Ly Corporation Yahoo! Shopping App For Android: before 14.15.0 (fixed in 14.15.0)

Published 2025-09-05. Last modified 2026-06-17.