VYPR
Unrated severityNVD Advisory· Published Jun 22, 2021· Updated Aug 3, 2024

CVE-2021-20733

CVE-2021-20733

Description

Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper authorization in custom URL scheme handler in asken diet Android app allows remote attackers to direct users to arbitrary websites, enabling phishing attacks.

Vulnerability

The asken diet app (あすけんダイエット) for Android versions from v.3.0.0 to v.4.2.x implements a custom URL scheme handler that does not properly restrict which URLs can be accessed. This flaw, classified as CWE-939 (Improper Authorization in Handler for Custom URL Scheme), allows the app to be directed to any arbitrary website without proper validation [1].

Exploitation

An attacker can craft a malicious URL using the app's custom URL scheme and trick a user into clicking it (user interaction required). The vulnerable app then navigates to the attacker-specified website without any additional authentication or authorization checks [1].

Impact

Successful exploitation leads the user to an arbitrary website, which could be a phishing site designed to steal credentials or personal information. The CVSS v3.0 base score is 4.3 (Medium) with vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N, indicating low integrity impact and no confidentiality or availability impact [1].

Mitigation

Users should update the asken diet app to the latest version according to the developer's instructions. The fixed version is not explicitly stated in the available references, but the vendor has addressed the issue in a subsequent release [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Asken/asken dietllm-create
    Range: 3.0.0 to 4.2.x
  • asken Inc./あすけんダイエット (asken diet) for Androidv5
    Range: versions from v.3.0.0 to v.4.2.x

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.