Improper Authorization in Myna Point Android App
CVE-2026-73335

4.6MEDIUM

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-73335?

The Myna Point Android application exhibits a vulnerability that allows for improper authorization in its handling of custom URL schemes. The flaw can be exploited by malicious applications installed on the same device, potentially leading to the execution of arbitrary JavaScript within the vulnerable app. This raises concerns about unauthorized access and control over user data and functionality, necessitating immediate attention from users and developers alike.

Affected Version(s)

Android App "Myna Point" 0 <= 2.0.6

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.