Executive brief
A security vulnerability exists in the My Location - Travel Timeline mobile application that allows a malicious app on the same device to overwrite the application's internal files. This could lead to the theft of sensitive travel data, application crashes, or the execution of unauthorized code. An attacker could exploit this by tricking a user into opening a malicious file or app, potentially compromising the integrity of the travel timeline service.
Technical details
A path traversal vulnerability (CWE-22) exists in the com.kaisquare.location.MainActivity component of the My Location - Travel Timeline app (v11.80). The flaw stems from insufficient validation of filenames and content during the file import process. A local attacker or malicious application can provide a crafted file that uses path traversal sequences to overwrite sensitive configuration or executable files within the app's internal storage. Successful exploitation can lead to arbitrary code execution, denial of service (app malfunction), or unauthorized access to sensitive information. The attack requires minimal user interaction and can be triggered when the victim interacts with a malicious application or file.
Affected products
- Squareapps LLC My Location - Travel Timeline 11.80
Timeline
- 2026-03-31: disclosed: Vulnerability disclosed by Secsys-FDU researchers.
- 2026-03-31: advisory: CVE-2026-30279 published.