Executive brief
A vulnerability in the neo.maru mobile application allows attackers to overwrite critical internal files during the file import process. This could lead to the application malfunctioning, the exposure of sensitive user data, or the execution of unauthorized code on the device. The flaw can be triggered automatically by a malicious application without requiring complex user interaction.
Technical details
An arbitrary file overwrite vulnerability exists in the neo.maru Android application (v2.0.23) within the 'my.geulga.ImageViewLauncher' component. The root cause is insufficient security validation when handling imported files, allowing a malicious application to use path traversal sequences to control filenames and paths within the app's internal storage. An attacker can exploit this to overwrite sensitive configuration or executable files. This can result in arbitrary code execution, denial of service, or unauthorized access to sensitive information. The attack requires no complex user interaction and can be triggered automatically once a victim opens a malicious application designed to interface with the vulnerable component.
Affected products
- MaruNuri LLC neo.maru 2.0.23
Timeline
- 2026-03-31: disclosed: Initial disclosure via GitHub issue and CVE assignment.
- 2026-03-31: advisory: NVD publication date.