CVE-2026-102671: Joyland AI WebView accepts invalid SSL certificates
Published Oct 1, 2026
·Updated
The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
Affected Software
1 affected component
Joyland AI Joyland AI app
Event History
Oct 1, 2026
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which part of the app is affected by the certificate-validation issue?
The issue is in the app's invisible advertisement WebView.
2
Does exploitation require an authenticated user or user interaction?
No. The provided vector indicates network access with no privileges and no user interaction required.
3
Is the vulnerable behavior enabled by default?
Yes. The invisible advertisement WebView accepts invalid SSL certificates by default.