CVE-2026-13461
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection o
CVSS
9.6
Critical
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: Jul 9, 2026 · Last modified: Jul 10, 2026
0.2%EPSS · 30 days0.3%
2026-07-102026-07-21
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
No related CVEs by CWE or product.