Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
Summary
| CVE | CVE-2026-12065 |
|---|---|
| State | PUBLISHED |
| Assigner | VulDB |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-12 14:16:30 UTC |
| Updated | 2026-06-12 16:16:27 UTC |
| Description | A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url scheme. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure. |
Risk And Classification
Primary CVSS: v4.0 0.3 LOW from [email protected]
CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-285 | CWE-939 | CWE-939 Improper Authorization in Handler for Custom URL Scheme | CWE-285 Improper Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 0.3 | LOW | CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/C... |
| 4.0 | CNA | DECLARED | 1 | LOW | CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| 3.1 | [email protected] | Secondary | 1.8 | LOW | CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | DECLARED | 1.8 | LOW | CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
| 3.0 | CNA | DECLARED | 1.8 | LOW | CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
| 2.0 | [email protected] | Secondary | 1 | AV:L/AC:H/Au:S/C:N/I:P/A:N | |
| 2.0 | CNA | DECLARED | 1 | AV:L/AC:H/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR |
CVSS v4.0 Breakdown
Attack Vector
PhysicalAttack Complexity
HighAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
NoneIntegrity
LowAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v3.0 Breakdown
Attack Vector
PhysicalAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Groww | Stock Mutual Fund Gold App | affected 20260805 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vuldb.com/vuln/370560 | [email protected] | vuldb.com | |
| drive.google.com/drive/folders/1r9t4AuG747PmRbgLmY2CztsX5PTjQL19 | [email protected] | drive.google.com | |
| github.com/honestcorrupt/Groww-Android-Application-Unsafe-WebView-URL-Ha... | [email protected] | github.com | |
| vuldb.com/cve/CVE-2026-12065 | [email protected] | vuldb.com | |
| vuldb.com/submit/822984 | [email protected] | vuldb.com | |
| github.com/honestcorrupt/CVE-req-Groww-Android-Application-Unsafe-WebVie... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | |
| vuldb.com/vuln/370560/cti | [email protected] | vuldb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: honest_corrupt (VulDB User) (en)
CNA: VulDB CNA Team (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-06-12T00:00:00.000Z | Advisory disclosed |
| CNA | 2026-06-12T02:00:00.000Z | VulDB entry created |
| CNA | 2026-06-12T09:38:15.000Z | VulDB entry last update |
There are currently no legacy QID mappings associated with this CVE.