Impact
The Joyland AI application uses an invisible advertisement WebView that, by default, accepts invalid SSL certificates. This flaw permits an attacker to supply a bogus certificate, allowing interception or tampering of data transmitted in the WebView and potentially injecting malicious content or stealing information. The weakness stems from improper certificate validation, as defined by CWE-295, and could compromise confidentiality and integrity of user traffic.
Affected Systems
The affected product is Joyland AI from Joyland. No specific version range is listed, so the default configuration in the available releases is impacted. Users of the Joyland AI app should verify the build and consult the vendor for any patch information.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability is moderately severe but not critical. The EPSS score is not available and the vulnerability is not yet listed in the CISA KEV catalog, indicating no confirmed exploitation yet. The attack vector is inferred to be remote, as the problem occurs over network connections to advertisement servers; a threat actor could perform a man‑in‑the‑middle by presenting a forged certificate to the device's advertisement WebView.
OpenCVE Enrichment