CVE-2026-22072
Arbitrary URL Loading in WebView Leading to Token Leakage Risk
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
| CWE | CWE-20 |
| Vendor | oppo |
| Product | oppo health |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for oppo oppo health
Be the first to know when new unknown vulnerabilities affecting oppo oppo health are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
OPPO / OPPO Health
6.2.9