By weakness (CWE)
CWE-939: related vulnerabilities
CVEs classified under CWE-939. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
3 published vulnerabilities
- CVE-2026-12189MEDIUM 5.3
Moovit Bus & Public Transit App version 1.18 on Android contains a flaw in its custom URL scheme handler that allows a local attacker with user-level privileges to bypass authorization controls. An attacker with access to the device could potentially read, modify, or disrupt app functionality by manipulating how the app processes custom URLs. The vulnerability requires local access and user interaction is not needed once access is gained. Public exploit code exists for this issue.
- CVE-2026-12190MEDIUM 5.3
A vulnerability in Genspark AI Workspace App version 2.8.4 on Android allows a local attacker with user-level access to bypass authorization checks for custom URL scheme handlers. This means an attacker already on the device could potentially redirect the app to perform actions it shouldn't allow, such as accessing sensitive data or triggering unintended operations. The attack requires local access and does not appear in active exploitation records.
- CVE-2026-12065LOW 1.8
A vulnerability in the Groww Stock, Mutual Fund, and Gold app (Android versions up to 20260805) allows attackers with physical access to a device to bypass authorization checks on custom URL schemes handled by the app's WebView component. An attacker would need to be present at the device and have some level of authentication context, making this a low-risk issue in typical operational environments. The issue affects the app's custom protocol handlers, which are entry points for inter-app communication on Android.