Vulnerability  ·  2026-10-03

Joyland AI companion app: WebView JS injection, hard-coded push credentials, and TLS/cleartext failures with no fix available (CVE-2026-102666-102671, 102667)

VulnerabilityHigh impactGlobalCVE-2026-102667
CISA published vulnerability advisory VA-26-275-03 on 2026-10-01 detailing seven CVEs in the Joyland AI companion app: WebView JavaScript injection (CVE-2026-102667, CVSS 8.3), hard-coded GeTui push credentials (CVE-2026-102666), unchecked TLS certificates, unverified hostnames, invalid-cert acceptance in the ad WebView, and cleartext HTTP allowance on Android 9+. No fix is available.
This is a consumer GenAI mobile app whose conversation surface can be turned into code execution with camera/GPS/mic/filesystem access on the same network, and whose push-credential leak lets an attacker blast arbitrary push notifications to every user. With no patch available, this is an unmitigated AI-app exposure worth flagging for anyone recommending or distributing the app.
Chain of client-side app flaws: injected JavaScript into content loaded in the WebView (clipboard access, arbitrary HTTP via Weex stream module, app-internal storage reads), hard-coded GeTui push credentials (send arbitrary push notifications to any/all users), acceptance of any TLS certificate, no hostname verification, and explicit cleartext-HTTP allowance.
Joyland AI app (Joyland.ai) — all versions, no fix available
No fix available (per CISA VA-26-275-03); uninstall or avoid the affected app on untrusted networks; treat AI-dialog content as untrusted.
CISA CSAF advisory VA-26-275-03NVD CVE-2026-102667
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →