VYPR

CWE-939

Improper Authorization in Handler for Custom URL Scheme

BaseIncomplete

Description

The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

Mobile platforms and other architectures allow the use of custom URL schemes to facilitate communication between applications. In the case of iOS, this is the only method to do inter-application communication. The implementation is at the developer's discretion which may open security flaws in the application. An example could be potentially dangerous functionality such as modifying files through a custom URL scheme.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (27)

page 1 of 2
  • CVE-2026-6445HigJun 9, 2026
    risk 0.57cvss epss 0.00

    A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.

  • CVE-2024-33606HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.00

    An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer system. User interaction is required to exploit this vulnerability.

  • CVE-2026-53408HigJun 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2026-53407HigJun 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2026-1046HigFeb 16, 2026
    risk 0.49cvss 7.6epss 0.00

    Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577

  • CVE-2026-35394HigApr 6, 2026
    risk 0.47cvss 8.3epss 0.00

    Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in mobile-mcp passes user-supplied URLs directly to Android's intent system without any scheme validation, allowing execution of arbitrary Android intents, including…

  • CVE-2021-31384HigOct 19, 2021
    risk 0.47cvss 7.2epss 0.01

    Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfaces can…

  • CVE-2026-33335HigMar 24, 2026
    risk 0.45cvss 8.0epss 0.00

    Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window.open()` calls directly to `shell.openExternal()` without any validation or protocol allowlisting.…

  • CVE-2026-3471MedMay 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}.…

  • CVE-2024-41918MedAug 29, 2024
    risk 0.40cvss 6.1epss 0.00

    'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable to improper authorization in handler for custom URL scheme. An arbitrary site may be displayed on the WebView of the product via Intent from another application…

  • CVE-2020-11000MedApr 8, 2020
    risk 0.37cvss 5.7epss 0.01

    GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verification wrong, which allows an attacker to circumvent the access…

  • CVE-2026-26123MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

  • CVE-2023-43582MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

  • CVE-2022-20736MedJun 15, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to…

  • CVE-2026-21075MedAug 10, 2026
    risk 0.34cvss epss 0.00

    Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.

  • CVE-2026-12190MedJun 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a…

  • CVE-2026-12189MedJun 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper authorization in handler for custom url scheme. The attack can only be executed locally. The…

  • CVE-2026-21062MedAug 10, 2026
    risk 0.31cvss epss 0.00

    Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

  • CVE-2025-41408MedSep 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote unauthenticated attacker may lead a user to access an arbitrary website on the vulnerable App. As a result, the user may become a victim…

  • CVE-2025-5020MedMay 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTTP schemes used internally by the Firefox iOS client. This vulnerability was fixed in Firefox for iOS 139.