Junglewise Threat Intelligence

CVE-2026-47782: Siber Systems RoboForm Password Manager insufficient intent validation in Android app

CVE-2026-47782 · Severity: low · CVSS 3.3 · Published 2026-05-20

Executive brief

RoboForm Password Manager for Android is a mobile application used to store and manage user credentials. A vulnerability in how the app handles requests from other applications could allow a malicious app installed on the same device to force RoboForm to download files from the internet without the user's knowledge or consent. This could be used to place unwanted or potentially harmful files on the user's device.

Technical details

The RoboForm Password Manager app for Android (versions 9.8.6.3 and prior) contains a vulnerability classified as Insufficient UI Warning of Dangerous Operations (CWE-357). The application accepts Android intents from other apps to open web pages but lacks sufficient URL validation and user confirmation mechanisms. A malicious application installed on the same device can send a crafted intent to RoboForm, causing it to navigate to a malicious URL and trigger a file download silently in the background without user notification. This requires the victim to have a malicious app installed that can interact with RoboForm's intent filters. The issue is addressed in version 9.9.5 and later.

Affected products

  • Siber Systems, Inc. RoboForm Password Manager 9.8.6.3 and prior

Timeline

  • 2026-05-20: disclosed: Vulnerability disclosed via JVN/JPCERT
  • 2026-05-20: patched: Version 9.9.5 released with security fixes
  • 2026-05-20: advisory

References