THE ESSENTIALS
  • September 14 is the disclosure date; the corrective release shipped August 31.

What changed

YAMAP disclosed an Android in-app browser vulnerability on September 14, affecting version 17.1.0 and earlier. The company says insufficient input checks and unnecessary permissions could let a malicious app already installed on the device expose internally stored information within the browser, display other websites or trigger unintended functions. It identifies version 17.2.0, distributed August 31, as the fix; iOS is unaffected.

Why it matters

The disclosure gives users a specific version boundary to check. It also explains the security significance of an update already available, rather than presenting the August software release as newly delivered.

What remains unproven

YAMAP says it found neither attacks exploiting the flaw nor a route transmitting the information externally. Those are findings from its investigation, not an independent assurance that exploitation never occurred.

THE EVIDENCE RECORD

Read beyond this page.

Recorded source-check date: 15 Sep 2026. A link is not, by itself, evidence that every claim has been independently verified.

  1. YAMAP ↗
  2. JVN iPedia / IPA ↗
Changes & version history

Version 3 · 15 Sep 2026
Scheduled release of checksum-bound AI-assisted editorial review

Version 2 · 15 Sep 2026
Checksum-bound editorial review scheduled for release

Version 1 · 15 Sep 2026
Source-linked private review edition

Request a correction ↗