CVE-2026-22077
Sensitive Information Disclosure Vulnerability Caused by Trusted Domain Bypass in OPPO Wallet
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.6EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
27 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information disclosure.
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:L/U:Amber
Affected products
OPPO · OPPO Wallet APPWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →