Executive brief
The Anshin Filter for au Android application, a parental control and web filtering tool, fails to encrypt sensitive data during transmission. This allows an attacker positioned on the same network, such as a public Wi-Fi hotspot, to intercept or modify the app's communications. This could lead to the exposure of private user information or the tampering of filtering settings.
Technical details
The Android application 'Anshin Filter for au' (versions prior to 4.9_b0003) is vulnerable to CWE-319 (Cleartext Transmission of Sensitive Information). The application fails to use encrypted protocols (like HTTPS) for certain sensitive communications, making it susceptible to Man-in-the-Middle (MitM) attacks. An unauthenticated attacker on the network path can capture plaintext traffic to disclose sensitive data or inject/modify data to tamper with the application's functionality. The vulnerability is addressed in version 4.9_b0003.
Affected products
- KDDI CORPORATION Anshin Filter for au (あんしんフィルター for au) prior to 4.9_b0003
Timeline
- 2026-05-13: advisory: JVN advisory published by JPCERT/CC
- 2026-05-14: disclosed: CVE published to NVD dataset