Executive brief
The Transsion AI Assistant Lifestyle application, a digital assistant found on Android devices, contains a security flaw in its web viewing component. A remote attacker can exploit this by sending a specially crafted link that, when processed by the app, executes malicious code within the application's interface. This could allow an attacker to access sensitive user information or perform unauthorized actions within the context of the assistant app.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the GeniexWebView component of the Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) on Android. The flaw is rooted in the improper neutralization of input within the 'web_action_data' URL parameter. A remote attacker can leverage this by crafting a malicious URL that, when handled by the application, executes arbitrary JavaScript in the WebView context. This vulnerability is classified as CWE-79 and affects all versions of the application. Users are advised to check for updates from the vendor, TECNOMobile.
Affected products
- Transsion AI Assistant Lifestyle (com.transsion.aiassistantlifestyle) All versions
Timeline
- 2026-06-02: disclosed: CVE published by TECNOMobile