CVE-2025-41408: Medium severity Yahoo Shopping App vulnerability
Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim of a phishing attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41408?
CVE-2025-41408 is categorized as a high severity vulnerability due to its potential for exploitation leading to phishing attacks.
How do I fix CVE-2025-41408?
To fix CVE-2025-41408, users should update the Yahoo Shopping App to version 14.15.0 or later.
Who is affected by CVE-2025-41408?
CVE-2025-41408 affects users of the Yahoo Shopping App for Android versions prior to 14.15.0.
What can attackers do with CVE-2025-41408?
Attackers exploiting CVE-2025-41408 can lead users to arbitrary websites, potentially enabling phishing attacks.
Is CVE-2025-41408 a local or remote vulnerability?
CVE-2025-41408 is a remote vulnerability that can be exploited by unauthenticated attackers.