Junglewise Threat Intelligence

CVE-2026-22077: OPPO Wallet APP trusted domain validation flaw

CVE-2026-22077 · Severity: info · CVSS 5.6 · Published 2026-04-27

Executive brief

The OPPO Wallet application, used for digital payments and financial services on mobile devices, contains a security flaw in how it verifies trusted web domains. An attacker could exploit this to bypass security restrictions and gain unauthorized access to protected parts of the app. This could lead to the theft of account login tokens and the exposure of sensitive personal or financial information.

Technical details

A vulnerability classified as an Origin Validation Error (CWE-346) exists in the OPPO Wallet application. The flaw stems from improper validation of trusted domains, which allows an attacker to bypass access restrictions on protected interfaces. Exploitation requires local access and user interaction, typically involving a high level of complexity to successfully intercept or spoof the validation logic. If successful, an attacker can hijack account tokens and access sensitive data stored within the application. The vulnerability was reported by OPPO with a CVSS 4.0 score of 5.6.

Affected products

  • OPPO Wallet APP

Timeline

  • 2026-04-27: disclosed
  • 2026-04-27: advisory

References