OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-102667 (CVSS 9.0)

NVD · officialPublished Oct 1, 2026Risk 50/100

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking.

CVSS
9.0
AV:AdjacentAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source