Impact
FairEmail’s AMP renderer called ActivityAMP processes AMP email content in a WebView. The renderer enables JavaScript execution but does not fully sanitize untrusted HTML. A crafted AMP message can inject inline scripts, event‑handler attributes or javascript: URLs that survive the incomplete cleaning. When the recipient turns on the AMP toggle and views the message, the malicious code runs inside the app’s WebView, allowing the attacker to read the DOM, exfiltrate information, and show phishing overlays.
Affected Systems
All installations of FairEmail by M66B released before version 1.2319 are affected, regardless of operating system version. The vendor is M66B and the product is FairEmail; users of any earlier Android build should verify their version.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS value is less than 1%, suggesting low likelihood of widespread exploitation in the near term. The vulnerability is not on the CISA KEV list, meaning no publicly known exploits have been confirmed. Attack requires user interaction: the message must be opened and the AMP toggle enabled. Because AMP emails are uncommon, practical exposure is limited, but an attacker who succeeds can gain client‑side control within the app.
OpenCVE Enrichment