SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-22072

HIGH · CVSS 8.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

WebView components are vulnerable to the loading of arbitrary external URLs, which can lead to the execution of malicious JavaScript code capable of stealing user tokens. This poses a significant security risk, particularly for applications that handle sensitive user data or authentication. Developers and security teams of affected applications should prioritize remediation to protect user information from potential exploitation.

CVE
CVE-2026-22072
Severity
HIGH
CVSS
8.3
EPSS
0.25%

Original NVD Description

Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.