CVE-2026-73335CWE-939

CVE-2026-73335

Medium · published August 26, 2026

CVSS v3.0
5.3
EPSS
0%
Percentile
2.8
In the wild
Unconfirmed
What it is

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.

The record
Technical detail
CVSS v3.0
5.3 · MEDIUM
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CVSS v4.0
4.6 · CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS
0.00128 · 2.8th percentile
Weakness
CWE-939 · Improper Authorization in Handler for Custom URL Scheme
Published
2026-08-26T09:18Z
References (2)
EPSS history
Timeline
  • 27 AUG 06:45Z
    EPSS moved — → 0%
    epss
  • 26 AUG 04:54Z
    Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939)
    cvelistv5