Skip to finding
important · Mobile

A permissionless Android app can silently redirect OsmAnd requests and disclose a user's locations.

Affects

OsmAnd for Android, a navigation and offline-mapping application

Crafted intent extras silently replace map-tile or routing endpoints, sending viewed coordinates and route origins and destinations to an attacker-controlled service.

Detail and 2 sources

The current upstream manifest still exports the activity, but exact affected and fixed releases remain unknown.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026