Executive brief
A security vulnerability exists in the Groww investment app for Android that could allow an unauthorized person with physical access to the device to bypass the app's passcode lock. By using specialized debugging tools, an attacker can force the app to open internal screens or display malicious websites within the trusted app interface. This could be used to trick users into entering sensitive information or to perform unauthorized actions within an active session.
Technical details
The Groww Android application (com.nextbillion.groww) fails to properly validate intent-based requests to the '.genesys.common.activities.WebActivity' component. An attacker with physical access and ADB debugging enabled can invoke this activity to bypass the local passcode lock and load arbitrary external URLs within the application's WebView. This allows for JavaScript execution in the context of the app and potential UI redressing or phishing attacks. The vulnerability is present in versions up to 20260805. While a public exploit exists, the attack complexity is high as it requires physical access and a privileged debugging environment.
Affected products
- Groww Groww Stock, Mutual Fund, Gold App up to 20260805
Timeline
- 2026-06-12: advisory: NVD publication date
References
- https://drive.google.com/drive/folders/1r9t4AuG747PmRbgLmY2CztsX5PTjQL19
- https://github.com/honestcorrupt/Groww-Android-Application-Unsafe-WebView-URL-Handling-Weak-Client-Side-App-Lock-Enforcement.git
- https://vuldb.com/cve/CVE-2026-12065
- https://vuldb.com/submit/822984
- https://vuldb.com/vuln/370560
- https://vuldb.com/vuln/370560/cti