Impact
The vulnerability is a cross‑site scripting flaw that allows an attacker to inject and execute arbitrary scripts inside the WebView component of the Miraikan Assist App. Injected scripts run with the app’s privileges and can arbitrarily alter the page content displayed to the user, potentially leading to further malicious actions within the app’s context.
Affected Systems
Miraikan Assist App for Android and iOS, published by the Japan Science and Technology Agency. No specific version information is disclosed; the flaw exists in the public releases available through official channels.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in KEV, suggesting no confirmed exploits yet. The likely attack vector requires a user to interact with a crafted link or page that loads inside the app’s WebView, meaning the exploit depends on user activity and the presence of untrusted content loaded by the app.
OpenCVE Enrichment