Improper Authorization in Myna Point Android App
CVE-2026-73335
4.6MEDIUM
What is CVE-2026-73335?
The Myna Point Android application exhibits a vulnerability that allows for improper authorization in its handling of custom URL schemes. The flaw can be exploited by malicious applications installed on the same device, potentially leading to the execution of arbitrary JavaScript within the vulnerable app. This raises concerns about unauthorized access and control over user data and functionality, necessitating immediate attention from users and developers alike.
Affected Version(s)
Android App "Myna Point" 0 <= 2.0.6
References
CVSS V4
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
CVSS V3.0
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
