JVN#67155805
Android App "Myna Point" vulnerable to improper access restriction
Overview
Android App "Myna Point" provided by Digital Agency contains an improper access restriction vulnerability.
Products Affected
- Android App "Myna Point" versions 2.0.6 and prior
Description
Android App "Myna Point" provided by Digital Agency contains the following vulnerability.
- Improper Authorization in Handler for Custom URL Scheme (CWE-939)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Base Score 4.6
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L Base Score 5.3
- CVE-2026-73335
Impact
A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.
Solution
Update the application
Update the application to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Digital Agency | Myna Point |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
RyotaK of GMO Flatt Security Inc. reported this vulnerability to the developer and IPA.
JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-73335 |
| JVN iPedia |
JVNDB-2026-000123 |