CVE-2026-12065
Last modified
CVE-2026-12065 is a low-severity vulnerability rated 1.8/10 on the CVSS scale. A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Metrics
CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-12065?
How severe is CVE-2026-12065?
How do I fix CVE-2026-12065?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12057When the application executes the JavaScript script embedded…7.8
- CVE-2026-12058The connection confirmation pop-up of a specific feature in …5.3
- CVE-2026-12059The SSH service of CelloOS developed by Cellopoint has an Im…8.8
- CVE-2026-1206The Elementor Website Builder plugin for WordPress is vulner…4.3
- CVE-2026-12060Heptabase developed by Hepta Platforms has a Exposed Dangero…6.9
- CVE-2026-12064When a user invokes curl using a schemeless URL combined wit…7.5
- CVE-2026-12066A security flaw has been discovered in PbootCMS up to 3.2.12…7.3
- CVE-2026-12068Information disclosure vulnerability in Avira Password Manag…7.4
- CVE-2026-1207An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.…5.4
- CVE-2026-12070Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a…8.4
- CVE-2026-12071The Webbox of TeamDavid by Tobit Laboratories AG constructs …5.3
- CVE-2026-12073The ProfileGrid – User Profiles, Groups and Communities plug…9.8
Are you affected by CVE-2026-12065?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
