Executive brief
DeftPDF Document Translator is a mobile application used to translate documents between different languages. A critical security flaw in version 54.0 allows an attacker to overwrite the app's internal files when a user imports a document. This could lead to the app being completely compromised, allowing attackers to steal sensitive information or execute malicious code on the device.
Technical details
An arbitrary file overwrite vulnerability exists in the DeftPDF Document Translator Android application (com.dftpdf.translate) version 54.0. The flaw is located in the file import process within the SplashScreenActivity component, where the application fails to properly validate filenames and paths provided during document ingestion. By exploiting this lack of validation, a malicious application or crafted file can utilize path traversal sequences to overwrite sensitive files within the app's internal storage. Successful exploitation can lead to arbitrary code execution if executable files or critical configurations are replaced, as well as information exposure or denial of service. The attack can be triggered automatically when a victim opens a malicious application that interacts with the vulnerable component.
Affected products
- DeftPDF (Sictec Infotech, Inc.) Document Translator (Android) 54.0
Timeline
- 2026-03-31: disclosed: Vulnerability disclosed by Secsys-FDU laboratory.
- 2026-03-31: advisory: CVE-2026-30276 published.