CWE-939: Improper Authorization in Handler for Custom URL Scheme
The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.
22 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-33606 — MicroDicom DICOM Viewer Improper Authorization in Handler for Custom URL Scheme
- CVE-2026-3471 — Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App
- CVE-2026-1046 — Arbitrary application execution via unvalidated server-controlled URLs in Help menu
- CVE-2026-6445 — A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information
- CVE-2026-35394 — Mobile Next has Arbitrary Android Intent Execution via mobile_open_url
- CVE-2026-53407 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.
- CVE-2026-53408 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.
- CVE-2026-33335 — Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal
- CVE-2025-41408 — Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.
- CVE-2026-12190 — Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
- CVE-2026-12189 — Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
- CVE-2026-73335 — Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A m
- CVE-2026-59717 — Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
- CVE-2025-67739 — In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
- CVE-2026-12065 — Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
Recently published
- CVE-2026-73335 — Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A m
- CVE-2026-59717 — Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
- CVE-2026-12190 — Genspark AI Workspace App ai.mainfunc.genspark improper authorization in handler for custom url scheme
- CVE-2026-12189 — Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custom url scheme
- CVE-2026-53408 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.
- CVE-2026-53407 — Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.
- CVE-2026-12065 — Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme
- CVE-2026-6445 — A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information
- CVE-2026-3471 — Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App
- CVE-2026-35394 — Mobile Next has Arbitrary Android Intent Execution via mobile_open_url
- CVE-2026-33335 — Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal
- CVE-2026-1046 — Arbitrary application execution via unvalidated server-controlled URLs in Help menu
- CVE-2025-67739 — In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
- CVE-2025-41408 — Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.
- CVE-2024-33606 — MicroDicom DICOM Viewer Improper Authorization in Handler for Custom URL Scheme