VYPR

CWE-939

Improper Authorization in Handler for Custom URL Scheme

BaseIncomplete

Description

The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

Mobile platforms and other architectures allow the use of custom URL schemes to facilitate communication between applications. In the case of iOS, this is the only method to do inter-application communication. The implementation is at the developer's discretion which may open security flaws in the application. An example could be potentially dangerous functionality such as modifying files through a custom URL scheme.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (27)

page 2 of 2
  • CVE-2024-45203MedSep 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to 6.74.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may…

  • CVE-2024-35298MedJun 19, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device. As a result, the user may become a victim…

  • CVE-2024-54014LowDec 5, 2024
    risk 0.23cvss 3.6epss 0.00

    Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead the application to access an arbitrary web site via another application installed on the user's…

  • CVE-2026-59717MedAug 7, 2026
    risk 0.21cvss 4.3epss 0.00

    Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without…

  • CVE-2024-54125LowDec 17, 2024
    risk 0.21cvss 3.3epss 0.00

    Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

  • CVE-2025-67739LowDec 11, 2025
    risk 0.20cvss 3.1epss 0.00

    In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

  • CVE-2026-12065LowJun 12, 2026
    risk 0.12cvss 1.8epss 0.00

    A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the…