Sceawere

Vulnerability Detail

CVE-2026-102667UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Joyland AI WebView JavaScript Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
1d ago
Vendor
Joyland
Product
Joyland.ai
Attack Type
CWE-749 Exposed Dangerous Method or Function
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-10-01T20:17:21.750Z",
  "pubdate": "2026-10-01T20:17:21.750Z",
  "executiveSummary": "The Joyland AI application is susceptible to a critical JavaScript injection vulnerability within its WebView component, stemming from improper security configurations that allow unauthorized code execution in the context of the application's origin.\nAn attacker with shared network access can intercept and manipulate traffic to inject malicious scripts into content rendered by the WebView.\nThis vulnerability exposes the application to significant risk, including unauthorized data exfiltration and device control.\nWithout explicit user-granted permissions, the attacker can leverage the Weex 'stream' module to perform unauthorized HTTP requests, access the system clipboard, and interact with internal application storage.\nIf the application has been previously granted elevated permissions, the impact escalates to full file system access, unauthorized camera and microphone usage, and persistent GPS tracking.\nThe attack is viable without authentication, relying solely on network proximity, making it a high-risk vector for malicious actors on local or shared network segments.",
  "technicalDetails": "The root cause of this vulnerability is the lack of proper origin validation and secure WebView configuration within the Joyland AI application. Specifically, the WebView fails to adequately sanitize or verify the source of the loaded content, allowing the execution of arbitrary JavaScript via man-in-the-middle (MITM) injection.\nThe exploitation process begins when an attacker positioned on the same network segment intercepts the application's traffic. By injecting malicious JavaScript payloads into the loaded web resources, the attacker gains a execution context within the WebView's origin.\nThe application leverages the Weex framework, which exposes powerful native-to-JavaScript bridge modules. The 'stream' module, in particular, is exposed to the WebView environment, enabling the injected script to perform arbitrary HTTP requests, potentially bypassing traditional CORS (Cross-Origin Resource Sharing) restrictions enforced by browsers.\nThe JavaScript context provides direct access to internal application storage and the system clipboard. In scenarios where the application manifest has requested and the user has previously approved sensitive system permissions (e.g., READ_EXTERNAL_STORAGE, CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION), the WebView's permissive configuration allows the injected script to bridge these permissions.\nAttack flow: 1) The attacker performs an ARP spoofing or DNS poisoning attack to intercept the application's unencrypted or poorly validated HTTP traffic. 2) The attacker injects a malicious payload into the served content. 3) The application's WebView parses the content and executes the injected JavaScript. 4) The script invokes the Weex 'stream' module or native Android/iOS APIs exposed through the JavaScript bridge to perform reconnaissance, exfiltrate local files, or activate hardware sensors such as the microphone, camera, or GPS.\nThe post-exploitation impact is severe, as the attacker achieves a persistent foothold on the device. By accessing the file system, the attacker can extract application databases, credentials, and user-sensitive documents. Furthermore, the ability to utilize the camera and microphone in the background allows for covert surveillance, significantly compromising user privacy and device integrity."
}
CVE-2026-102667: Joyland AI WebView JavaScript Injection (HIGH Severity, CVSS: 8.3) | Sceawere