Back to overview

CVE-2026-13514

LOW
2.4
CVSS 3.1
Description
A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file to an unauthorized control sphere. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be used for attacks. Upgrading the affected component is advised. The vendor was informed early about this issue. They confirmed the existence and that they will address it. Furthermore, they explain that their bug bounty "explicitly excludes physical-access attacks". However, they appreciate the quality of the report and aim at making a goodwill payment to the researcher.

Metadata

CVE ID
CVE-2026-13514
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-28 06:40 UTC
Published
2026-06-28 23:15 UTC
Last updated
2026-06-28 23:15 UTC
Primary CWE
CWE-530
Exposure of Backup File to an Unauthorized Control Sphere
Vendor / Product
Chess / Play and Learn App
Sources
cve.org  ·  NVD

Severity & Metrics

2.4 LOW CVSS 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
Affected products (1)
VendorProductPlatformVersions
Chess Play and Learn App 4.9.0, 4.9.1, 4.9.2, 4.9.3 …
Weakness (CWE)
CWESourceDescription
CWE-285 cna Improper Authorization
CWE-530 cna Exposure of Backup File to an Unauthorized Control Sphere
CVSS scores (4)
ScoreSeverityVersionSourceVector
2.4 LOW 4.0 cna CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
2.4 LOW 3.1 cna CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
2.4 LOW 3.0 cna CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
2.1 N/D 2.0 cna AV:L/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C
References (6)
Back to overview