What is CVE-2026-22072?
CVE-2026-22072 is a vulnerability involving the loading of arbitrary external URLs through WebView components. This allows the injection of malicious JavaScript code, which can result in the theft of arbitrary user tokens. It is recommended to enforce URL loading restrictions on affected systems.
Azərbaycanca: CVE-2026-22072 WebView komponentləri vasitəsilə ixtiyari xarici URL-lərin yüklənməsi ilə bağlı zəiflikdir. Bu, zərərli JavaScript kodunun tətbiqinə şərait yaradaraq istifadəçi tokenlərinin oğurlanmasına səbəb ola bilər. Təsirə məruz qalan sistemlərdə URL yükləmə məhdudiyyətlərinin tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How can CVE-2026-22072 be exploited?
This vulnerability allows loading arbitrary external URLs through WebView components, enabling attackers to inject malicious JavaScript code and steal arbitrary user tokens.
What is the recommended mitigation for CVE-2026-22072?
It is recommended to enforce URL loading restrictions on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.