CVE-2026-73335: Medium severity Myna Point vulnerability
Published Aug 26, 2026
·Updated
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.
Affected Software
1 affected component
Myna Point
Event History
Aug 26, 2026
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
DescriptionSeverity
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
A malicious application must already be installed on the same Android device as Myna Point. It can then invoke affected functionality through an Intent; user interaction is also required according to the CVSS vector.
2
What could exploitation allow?
The issue may allow arbitrary JavaScript to execute within the affected Myna Point application. The stated impact includes limited effects on confidentiality, integrity, and availability.