Arbitrary External URL Loading Vulnerability in OPPO Products
CVE-2025-27388
8.3HIGH
What is CVE-2025-27388?
A vulnerability has been identified in OPPO mobile devices that permits loading arbitrary external URLs via WebView components. This security flaw can be exploited to inject malicious JavaScript code, potentially compromising user security by stealing sensitive tokens. Users of affected OPPO devices may be at risk, as this flaw can facilitate unauthorized access to user information and other critical data.
Affected Version(s)
OPPO HEALTH APP 4.23.4 and below <= 4.23.4