CVE-2019-5955
Description
CREATE SD official App for Android version 1.0.2 and earlier allows remote attackers to bypass access restriction to lead a user to access an arbitrary website via vulnerable application and conduct phishing attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CREATE SD official App for Android 1.0.2 and earlier fails to restrict Intent access, enabling phishing attacks via arbitrary URL launches.
Vulnerability
CREATE SD official App for Android version 1.0.2 and earlier contains an improper access control vulnerability (CWE-284) in the function that handles URL access via an Intent [1]. The app does not properly restrict which applications can send an Intent to it, allowing any arbitrary app on the device to invoke the vulnerable function [1].
Exploitation
An attacker can exploit this vulnerability by crafting a malicious Android application that sends a crafted Intent to the CREATE SD official App. The attack requires the attacker to install the malicious app on the user's device or trick the user into installing it [1]. No authentication or special privileges beyond normal Android app permissions are needed. The attacker then uses the Intent to direct the vulnerable app to open an arbitrary URL chosen by the attacker [1].
Impact
A remote attacker can lead the user of the vulnerable app to access an arbitrary website without the user's informed consent. This can be used to conduct phishing attacks, where the user is directed to a malicious site that may steal credentials or other sensitive information [1]. The CVSS v3 score is 3.0 (Low), with vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N, indicating limited impact but requiring user interaction [1].
Mitigation
The developer has released an updated version of the application. Users should update to the latest version of CREATE SD official App for Android as provided by the developer [1]. No workarounds beyond updating are described in the available reference.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.0.2
- CREATE S.D CO., LTD./CREATE SD official App for Androidv5Range: version 1.0.2 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN87655507/index.htmlmitrex_refsource_MISC
- www.create-sd.co.jp/Portals/0/pdf/appsec_en.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.