🚨 CVE-2026-84431
A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The attack requires a local approach. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
Google Docs
AirAsia_MOVE_CWE-22_DirtyStream_VulDB.docx
AirAsia MOVE App up to 12.47.1 Intent getRealPath _display_name Path Traversal Vulnerability Database Entry · Prepared by Actuator Security (actuator.sh) · 2026-07-09 ENTRY VulDB-ID pending submission CVE requested – pending assignment Assigning CNA Vuldb…

September 2, 2026 6