CVE-2026-13461
9.6PayRange · PayRange
A critical code injection vulnerability exists in the PayRange mobile application, allowing attackers to escape the WebView sandbox and execute arbitrary actions on the user's device.
Executive summary
The PayRange mobile application contains a critical code injection vulnerability that allows unauthorized device-level actions when paired with an SSL bypass.
Vulnerability
This vulnerability is a code injection flaw (CWE-94) triggered via the injection of malicious JavaScript into a WebView component. The attack is unauthenticated and requires user interaction to facilitate the sandbox escape.
Business impact
The potential impact of this vulnerability is severe, as it grants an attacker the ability to perform unauthorized actions on the host device, leading to potential data exfiltration or total compromise of the application environment. Given the critical CVSS score of 9.6, this flaw presents a significant risk to user privacy and device integrity. Failure to remediate could result in widespread exploitation of the application user base.
Remediation
Immediate Action: Users and administrators should update the PayRange application to the latest available version as soon as a patch is released by the vendor.
Proactive Monitoring: Security teams should monitor mobile application logs for anomalous WebView activity or unexpected JavaScript execution patterns that deviate from standard application behavior.
Compensating Controls: Ensure that all mobile device management (MDM) policies are strictly enforced and consider using network-level security controls to prevent the exploitation of the associated SSL bypass vulnerability.
Exploitation status
Public Exploit Available: No confirmed public exploit is available.
Analyst recommendation
This vulnerability represents a critical risk to the PayRange ecosystem, necessitating immediate attention. Organizations should prioritize updating the application to the latest version immediately upon vendor release. Given the severity of the impact, users should exercise extreme caution with untrusted network environments until a fix is confirmed and deployed.