CVE-2026-84431: Airasia Move App

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • Airasia Move App: version 12.47.0 only; version 12.47.1 only

Published 2026-09-02. Last modified 2026-09-02.