Impact
The Android app "Myna Point" contains an improper authorization flaw in its handler for a custom URL scheme. Because the system does not properly authenticate the source of an Intent, a malicious application on the same device can send a crafted Intent that causes the victim app to execute arbitrary JavaScript code. The vulnerability is identified as CWE‑939 and allows the attacker to run code inside the application’s JavaScript context, potentially leading to data leakage, credential theft, or tampering of app behavior.
Affected Systems
The affected product is the Android application Myna Point, distributed by Digital Agency. No specific version information is included in the advisory, so all releases of the app are potentially impacted until an update is released by the vendor.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate level of risk. EPSS data is not available, so the probability of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a local exploitation scenario: an attacker must install a malicious application on the user’s device and trigger the vulnerable intent. Because the flaw relies on an unauthorized Intent handler rather than a network‑based vector, it is unlikely to be exploited remotely without the user running a secondary malicious app on the device.
OpenCVE Enrichment