CVE-2026-47782 Details
Description
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification.
A vulnerability exists in the Android app "RoboForm Password Manager" by Siber Systems, Inc., affecting versions through 9.8.6.3. The app improperly manages Android intents, lacking adequate URL validation, user confirmation, and notification. This flaw allows malicious URLs to be sent via intents, potentially leading to silent file downloads without user awareness.
Users are advised to update the app to the latest version available on the Google Play Store.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 20, 2026CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU93461473/ | [email protected] | AdvisoryRemedy |
| https://play.google.com/store/apps/details?id=com.siber.roboform | [email protected] | ProductVendor |
| https://www.roboform.com/news-android | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-357 | Insufficient UI Warning of Dangerous Operations | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siber Systems RoboForm Password Manager | <= 9.8.6.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2026 | New CVE Received | [email protected] |
Volerion