Executive brief
HCL Verse for Android, a mobile email client for business users, contains a security flaw in its email composition tool. This vulnerability could allow malicious content to be executed when a user interacts with specially crafted rich text emails. If exploited, an attacker could potentially gain unauthorized access to sensitive email data or perform actions on behalf of the user.
Technical details
An improper input validation vulnerability (CWE-20) and cross-site scripting (XSS) flaw (CWE-79) exist in the compose-rich-editor library (v1.0.0-rc14) used by HCL Verse for Android. The vulnerability is triggered when the application fails to properly sanitize HTML input during rich text email composition. An attacker can exploit this by delivering malicious HTML content that, when processed by the editor, executes in the context of the application. Exploitation requires user interaction and occurs under specific conditions (high complexity), potentially leading to a loss of confidentiality and integrity of user data. The issue is confirmed in version 14.5.10.
Affected products
- HCL Software Verse for Android 14.5.10
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory