Executive brief
Myna Point is an Android application used by Japanese government personnel and citizens. A malicious app installed on the same device can exploit this vulnerability to execute arbitrary JavaScript code within Myna Point, potentially allowing an attacker to steal sensitive data, bypass security controls, or perform unauthorized actions on behalf of the user.
Technical details
The vulnerability is an improper authorization flaw in the application's custom URL scheme handler (CWE-939). A malicious application installed on the user's Android device can craft a specially crafted Intent to invoke the vulnerable handler without proper authorization checks. This allows arbitrary JavaScript execution within the Myna Point application context, potentially granting the attacker access to sensitive data or functionality. The vulnerability requires a malicious app already installed on the device and user interaction (opening a link or receiving an intent). A patch is available by updating to the latest version.
Affected products
- Digital Agency Myna Point 2.0.6 and prior
Timeline
- 2026-08-26: disclosed