Impact
The vulnerability arises from the Joyland AI application explicitly permitting cleartext HTTP traffic on Android devices running version 9 or later, contrary to the default Android behavior that blocks such traffic. This flaw is a classic example of the Cleartext Transmission of Sensitive Information weakness (CWE‑319) and enables attackers to intercept or modify data transmitted over the network without encryption, potentially exposing user credentials, personal data, or other sensitive information. The impact is primarily data exposure rather than code execution or system compromise.
Affected Systems
Affected parties are users of the Joyland AI application, a mobile app distributed by Joyland: Joyland.ai, deployed on Android 9+ devices. Specific version ranges are not listed in the CVE, so all releases running on these Android versions remain potentially vulnerable until the vendor addresses the issue.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, but the lack of an EPSS score and absence from the KEV catalog suggest that exploitation is not widespread so far. Attackers would likely need to position themselves on the same network to capture traffic, or exploit a man‑in‑the‑middle scenario, as the application does not enforce TLS. The vulnerability can be exploited by any entity that can sniff the network; no privileged access or privileged code execution is required. Hence, the risk remains moderate with a potential for data leakage in exposed network environments.
OpenCVE Enrichment