CVE-2026-13461
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection o
CVSS
9.6
Crítico
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Publicado: 9 jul 2026 · Última mod.: 10 jul 2026
0.2%EPSS · 30 días0.3%
2026-07-102026-07-21
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
Sin CVEs relacionados por CWE o producto.