What is CVE-2026-21075?
CVE-2026-21075 is a vulnerability in My Galaxy prior to version 6.3, where improper authorization in the handler for a custom URL scheme allows remote attackers to access sensitive information. This can lead to data leakage when a specially crafted link is processed by the app. It is recommended to update My Galaxy to version 6.3 or later.
Azərbaycanca: CVE-2026-21075, My Galaxy tətbiqinin 6.3-dən əvvəlki versiyalarında xüsusi URL sxemi işləyicisində düzgün olmayan avtorizasiya səbəbindən uzaq hücumçulara həssas məlumatlara giriş imkanı verən zəiflikdir. Bu, tətbiq vasitəsilə xüsusi linklər işlədildikdə məlumat sızmasına yol aça bilər. My Galaxy tətbiqini 6.3 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which application is affected by CVE-2026-21075 and how is it exploited?
The vulnerability affects the My Galaxy app. Remote attackers can exploit improper authorization in a custom URL scheme handler to access sensitive information when a specially crafted link is processed by the app.
What should be done to protect against CVE-2026-21075?
It is recommended to update the My Galaxy app to version 6.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.