By weakness (CWE)
CWE-939: related vulnerabilities
CVEs classified under CWE-939. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
5 published vulnerabilities
- CVE-2026-53407HIGH 8.1
Zoom Workplace for mobile devices contains an authorization flaw in how it handles custom URL schemes. An attacker with network access and valid Zoom credentials could craft a malicious link or request that bypasses intended security controls, allowing them to escalate their privileges within the application. The vulnerability affects Android versions before 7.0.4 and iOS versions before 7.0.3. While this requires some form of authentication to exploit, the impact allows an attacker to gain elevated access they shouldn't normally have.
- CVE-2026-53408HIGH 8.1
Zoom Workplace for Android and iOS contains a flaw in how it handles custom URL schemes, allowing someone with network access to bypass normal authorization checks and gain elevated privileges on the device. An unauthenticated attacker can craft a malicious link or redirect that exploits this improper authorization logic, potentially gaining access to sensitive features or data within the app without proper authentication. This affects Android versions before 7.0.4 and iOS versions before 7.0.3.
- CVE-2026-12189MEDIUM 5.3
Moovit Bus & Public Transit App version 1.18 on Android contains a flaw in its custom URL scheme handler that allows a local attacker with user-level privileges to bypass authorization controls. An attacker with access to the device could potentially read, modify, or disrupt app functionality by manipulating how the app processes custom URLs. The vulnerability requires local access and user interaction is not needed once access is gained. Public exploit code exists for this issue.
- CVE-2026-12190MEDIUM 5.3
A vulnerability in Genspark AI Workspace App version 2.8.4 on Android allows a local attacker with user-level access to bypass authorization checks for custom URL scheme handlers. This means an attacker already on the device could potentially redirect the app to perform actions it shouldn't allow, such as accessing sensitive data or triggering unintended operations. The attack requires local access and does not appear in active exploitation records.
- CVE-2026-12065LOW 1.8
A vulnerability in the Groww Stock, Mutual Fund, and Gold app (Android versions up to 20260805) allows attackers with physical access to a device to bypass authorization checks on custom URL schemes handled by the app's WebView component. An attacker would need to be present at the device and have some level of authentication context, making this a low-risk issue in typical operational environments. The issue affects the app's custom protocol handlers, which are entry points for inter-app communication on Android.