Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 1epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
Groww · Stock, Mutual Fund, Gold Apppublic PoCs found — 2
cve_referencedrive.google.com/drive/folders/1r9t4AuG747PmRbgLmY2CztsX5PTjQL19unverifiedcve_referencegithub.com/honestcorrupt/CVE-req-Groww-Android-Application-Unsafe-WebView-URL-Handling-Weak-Client-Side-App-Lock-Enforcementunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://drive.google.com/drive/folders/1r9t4AuG747PmRbgLmY2CztsX5PTjQL19https://github.com/honestcorrupt/CVE-req-Groww-Android-Application-Unsafe-WebView-URL-Handling-Weak-Client-Side-App-Lock-Enforcementhttps://github.com/honestcorrupt/Groww-Android-Application-Unsafe-WebView-URL-Handling-Weak-Client-Side-App-Lock-Enforcement.githttps://vuldb.com/cve/CVE-2026-12065https://vuldb.com/submit/822984https://vuldb.com/vuln/370560https://vuldb.com/vuln/370560/cti