CVE-2026-22072EPSS p34.8%

CVE-2026-22072CVE-2026-22072

Description

Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.

Scoring

EPSS0.43% probability of exploitation · percentile 34.8% · 2026-10-05T12:00:23Z
Last modified2026-09-03
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.