Improper Authorization in Moovit Bus & Public Transit App on Android
CVE-2026-12189
Key Information:
- Vendor
Moovit
- Status
- Vendor
- CVE Published:
- 14 June 2026
Badges
What is CVE-2026-12189?
A vulnerability exists in the Moovit Bus & Public Transit App version 1.18 for Android, related to improper authorization within the component com.tranzmate. This flaw enables local attackers to exploit the URL scheme handler, which can lead to unauthorized actions within the application. The exploitation requires physical access to the device, making it crucial for users to be aware of security implications, as exploit methods have been publicly disclosed and the vendor has not acknowledged the issue. Awareness and proactive measures are essential for safeguarding sensitive user data.
Affected Version(s)
Bus & Public Transit App 1.18
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
