CWE-939Base

Improper Authorization in Handler for Custom URL Scheme

Incomplete in the CWE catalog · 24 CVEs mapped

24
CVEs mapped
5.4
Median CVSS
What it is

The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

Recent examples
5.3cvss
CVE-2026-73335

CVE-2026-73335 - MEDIUM Severity Vulnerability

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.

MEDIUMno explanation yet
0%
epss
none
CVE-2026-21075

CVE-2026-21075 - UNKNOWN Severity Vulnerability

Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.

no explanation yet
0%
epss
3.3cvss
CVE-2026-21062

CVE-2026-21062 - LOW Severity Vulnerability

Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-939
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)