Published:2026/08/26  Last Updated:2026/08/26

JVN#67155805
Android App "Myna Point" vulnerable to improper access restriction

Overview

Android App "Myna Point" provided by Digital Agency contains an improper access restriction vulnerability.

Products Affected

  • Android App "Myna Point" versions 2.0.6 and prior

Description

Android App "Myna Point" provided by Digital Agency contains the following vulnerability.

  • Improper Authorization in Handler for Custom URL Scheme (CWE-939)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Base Score 4.6
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L Base Score 5.3
    • CVE-2026-73335

Impact

A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.

Solution

Update the application
Update the application to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
Digital Agency Myna Point

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

RyotaK of GMO Flatt Security Inc. reported this vulnerability to the developer and IPA.
JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-73335
JVN iPedia JVNDB-2026-000123