JavaScript Execution Vulnerability in FairEmail for Android
CVE-2026-54521

6.1MEDIUM

Key Information:

Vendor

M66b

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54521?

FairEmail, a privacy-focused email application for Android, has a vulnerability in its ActivityAMP message renderer before version 1.2319. This flaw allows for the execution of arbitrary JavaScript through improperly sanitized HTML in AMP messages. When users enable the AMP toggle, a crafted AMP email can lead to malicious script execution. This script could potentially access message data or present phishing overlays, posing risks to user privacy. Users are advised to update to the latest version (1.2319) to mitigate this issue.

Affected Version(s)

FairEmail < 1.2319

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.