CyberRota Analysis
AI-GeneratedWebView components are vulnerable to the loading of arbitrary external URLs, which can lead to the execution of malicious JavaScript code capable of stealing user tokens. This poses a significant security risk, particularly for applications that handle sensitive user data or authentication. Developers and security teams of affected applications should prioritize remediation to protect user information from potential exploitation.
CVE
CVE-2026-22072
Severity
HIGH
CVSS
8.3
EPSS
0.25%
Original NVD Description
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.