Junglewise Threat Intelligence

CVE-2026-84431: AirAsia MOVE App path traversal in getRealPath

CVE-2026-84431 · Severity: medium · CVSS 4.4 · Published 2026-09-02

Executive brief

AirAsia MOVE is a mobile payment and travel booking app used by millions of users. A path traversal vulnerability in the app's file-sharing handler allows a malicious app on the same device to write arbitrary files into the app's internal storage, potentially corrupting app data, injecting malicious configurations, or causing the app to crash. No user action or authentication is required for the attack.

Technical details

The vulnerability exists in the getRealPath() function of com.airasia.core.utils.RealPathUtil, which handles incoming file-sharing intents. The function copies files into the app's cache directory using the provider-supplied _display_name parameter without any sanitization or path validation. An attacker can supply a traversal sequence (e.g., "../files/x") as the _display_name to escape the cache directory and write files into sibling directories under the app sandbox (/data/data/com.airasia.mobile/). The attack vector is local—requiring a co-installed malicious application—and requires no authentication or user interaction. An attacker gains arbitrary file write access within the application sandbox, allowing integrity violations and potential availability impact. No patch has been released; the vendor did not respond to early disclosure.

Affected products

  • AirAsia MOVE up to 12.47.1

Timeline

  • 2026-09-02: disclosed: CVE-2026-84431 published
  • 2026-07-09: other: Vulnerability documented with confirmed PoC bytecode analysis

References