CVE-2021-20733
Description
Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper authorization in custom URL scheme handler in asken diet Android app allows remote attackers to direct users to arbitrary websites, enabling phishing attacks.
Vulnerability
The asken diet app (あすけんダイエット) for Android versions from v.3.0.0 to v.4.2.x implements a custom URL scheme handler that does not properly restrict which URLs can be accessed. This flaw, classified as CWE-939 (Improper Authorization in Handler for Custom URL Scheme), allows the app to be directed to any arbitrary website without proper validation [1].
Exploitation
An attacker can craft a malicious URL using the app's custom URL scheme and trick a user into clicking it (user interaction required). The vulnerable app then navigates to the attacker-specified website without any additional authentication or authorization checks [1].
Impact
Successful exploitation leads the user to an arbitrary website, which could be a phishing site designed to steal credentials or personal information. The CVSS v3.0 base score is 4.3 (Medium) with vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N, indicating low integrity impact and no confidentiality or availability impact [1].
Mitigation
Users should update the asken diet app to the latest version according to the developer's instructions. The fixed version is not explicitly stated in the available references, but the vendor has addressed the issue in a subsequent release [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 3.0.0 to 4.2.x
- asken Inc./あすけんダイエット (asken diet) for Androidv5Range: versions from v.3.0.0 to v.4.2.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/jp/JVN38034268/index.htmlmitrex_refsource_MISC
- www.asken.jp/s/login/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.