- September 14 is the disclosure date; the corrective release shipped August 31.
What changed
YAMAP disclosed an Android in-app browser vulnerability on September 14, affecting version 17.1.0 and earlier. The company says insufficient input checks and unnecessary permissions could let a malicious app already installed on the device expose internally stored information within the browser, display other websites or trigger unintended functions. It identifies version 17.2.0, distributed August 31, as the fix; iOS is unaffected.
Why it matters
The disclosure gives users a specific version boundary to check. It also explains the security significance of an update already available, rather than presenting the August software release as newly delivered.
What remains unproven
YAMAP says it found neither attacks exploiting the flaw nor a route transmitting the information externally. Those are findings from its investigation, not an independent assurance that exploitation never occurred.
Read beyond this page.
Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.
Changes & version history
Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review
Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release
Version 1 · 15 Sep 2026
Source-linked private review edition
