Sceawere
Vulnerability Detail
CVE-2026-102667UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Joyland AI WebView JavaScript Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.3
- Creation Date
- 1d ago
- Vendor
- Joyland
- Product
- Joyland.ai
- Attack Type
- CWE-749 Exposed Dangerous Method or Function
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.3",
"pubDate": "2026-10-01T20:17:21.750Z",
"pubdate": "2026-10-01T20:17:21.750Z",
"executiveSummary": "The Joyland AI application is susceptible to a critical JavaScript injection vulnerability within its WebView component, stemming from improper security configurations that allow unauthorized code execution in the context of the application's origin.\nAn attacker with shared network access can intercept and manipulate traffic to inject malicious scripts into content rendered by the WebView.\nThis vulnerability exposes the application to significant risk, including unauthorized data exfiltration and device control.\nWithout explicit user-granted permissions, the attacker can leverage the Weex 'stream' module to perform unauthorized HTTP requests, access the system clipboard, and interact with internal application storage.\nIf the application has been previously granted elevated permissions, the impact escalates to full file system access, unauthorized camera and microphone usage, and persistent GPS tracking.\nThe attack is viable without authentication, relying solely on network proximity, making it a high-risk vector for malicious actors on local or shared network segments.",
"technicalDetails": "The root cause of this vulnerability is the lack of proper origin validation and secure WebView configuration within the Joyland AI application. Specifically, the WebView fails to adequately sanitize or verify the source of the loaded content, allowing the execution of arbitrary JavaScript via man-in-the-middle (MITM) injection.\nThe exploitation process begins when an attacker positioned on the same network segment intercepts the application's traffic. By injecting malicious JavaScript payloads into the loaded web resources, the attacker gains a execution context within the WebView's origin.\nThe application leverages the Weex framework, which exposes powerful native-to-JavaScript bridge modules. The 'stream' module, in particular, is exposed to the WebView environment, enabling the injected script to perform arbitrary HTTP requests, potentially bypassing traditional CORS (Cross-Origin Resource Sharing) restrictions enforced by browsers.\nThe JavaScript context provides direct access to internal application storage and the system clipboard. In scenarios where the application manifest has requested and the user has previously approved sensitive system permissions (e.g., READ_EXTERNAL_STORAGE, CAMERA, RECORD_AUDIO, ACCESS_FINE_LOCATION), the WebView's permissive configuration allows the injected script to bridge these permissions.\nAttack flow: 1) The attacker performs an ARP spoofing or DNS poisoning attack to intercept the application's unencrypted or poorly validated HTTP traffic. 2) The attacker injects a malicious payload into the served content. 3) The application's WebView parses the content and executes the injected JavaScript. 4) The script invokes the Weex 'stream' module or native Android/iOS APIs exposed through the JavaScript bridge to perform reconnaissance, exfiltrate local files, or activate hardware sensors such as the microphone, camera, or GPS.\nThe post-exploitation impact is severe, as the attacker achieves a persistent foothold on the device. By accessing the file system, the attacker can extract application databases, credentials, and user-sensitive documents. Furthermore, the ability to utilize the camera and microphone in the background allows for covert surveillance, significantly compromising user privacy and device integrity."
}