Executive brief
Traccar Client is a mobile application used for GPS tracking and telemetry. A vulnerability in the app allows an attacker to silently hijack the device's tracking settings by tricking a user into clicking a specially crafted link. Once clicked, the app will automatically redirect all real-time location data to a server controlled by the attacker without any notification or confirmation from the user.
Technical details
Traccar Client (versions 9.7.19 and below) registers a custom deep-link scheme (org.traccar.client://config) that processes configuration parameters without user confirmation or source validation (CWE-940). An attacker can craft a URI containing parameters such as 'url', 'id', 'accuracy', and 'interval'. When the victim interacts with this link (via SMS, email, or a malicious webpage), the app's intent handler silently overwrites the persistent SharedPreferences configuration. This allows an unauthenticated remote attacker to redirect all GPS telemetry to a malicious endpoint at maximum precision. The change persists across application restarts and provides no visual indication of the hijack in the primary UI due to cached state. The issue is resolved in version 9.7.20 by adding a configuration confirmation dialog.
Affected products
- traccar traccar-client <= 9.7.19
Timeline
- 2026-05-22: disclosed: Initial disclosure to vendor via GitHub Advisory
- 2026-06-17: advisory: Public advisory and CVE assignment
- 2026-06-17: patched: Fixed in version 9.7.20