CVE-2026-102667

Published: Ott 01, 2026 Last Modified: Ott 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,0
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 8,3
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Attack Vector: adjacent_network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking.

749

Exposed Dangerous Method or Function

Incomplete
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Access Control Other
Potential Impacts:
Gain Privileges Or Assume Identity Read Application Data Modify Application Data Execute Unauthorized Code Or Commands Other
Applicable Platforms
All platforms may be affected
View CWE Details
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026…
https://www.cve.org/CVERecord?id=CVE-2026-1026667