Impact
The PayRange Android application, versions 7.0.7 and earlier, contains an SSL bypass flaw in its embedded webview component. The app accepts invalid or self‑signed SSL/TLS certificates without validation, allowing the app to establish a trust relationship with an attacker‑controlled server. This weakness, mapped to CWE-295, permits a remote attacker to intercept, capture, or modify the that the user transmits through the application.
Affected Systems
Any user running the PayRange Android app version 7.0.7 or earlier on an Android device is affected. The vulnerability resides in the application’s webview and is independent of the device model or base Android OS version.
Risk and Exploitability
The CVSS score of 7.5 reflects high severity, while the EPSS score of < 1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. A remote, unauthenticated attacker can exploit the flaw by hosting a malicious server that presents a forged certificate; because the app trusts this certificate, the attacker can intercept or tamper with traffic to the legitimate server. The likely attack vector is therefore remote network traffic interception through the compromised webview, as the app accepts certificates presented by any remote server.
OpenCVE Enrichment