CVE detail
CVE-2021-20835 — CVE-2021-20835
Published 2021-11-24 · Modified 2026-06-17 · Vendor mercari · Product mercari · Source nvd
HIGH
severity
CVSS-derived band
0.0133
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches an arbitrary Activity of the app via the vulnerable App, which may result in Mercari account's access token being obtained.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References