CVE-2026-22072

8.3

OPPO · OPPO Health

A vulnerability in the OPPO Health application allows the loading of arbitrary external URLs within WebView components, leading to potential token theft.

Executive summary

The OPPO Health application is vulnerable to arbitrary URL loading in its WebView component, which can be leveraged to steal sensitive user authentication tokens.

Vulnerability

The application fails to properly validate input when loading URLs in WebView components. This allows an unauthenticated attacker to inject malicious JavaScript code into the user session, facilitating the theft of sensitive session tokens.

Business impact

The ability for an attacker to steal user tokens creates a significant risk of unauthorized account access and data compromise. With a CVSS score of 8.3, this vulnerability is critical for mobile users who store sensitive health data within the application, as the impact includes potential leakage of private information.

Remediation

Immediate Action: Check the official OPPO security portal for the latest application update and install version 6.2.9 or later if available.

Proactive Monitoring: Review application access logs for unusual redirects or connections to unauthorized external domains.

Compensating Controls: Use mobile device management (MDM) policies to restrict network traffic for the application if an update is not immediately available.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Users of the OPPO Health application should remain vigilant and apply updates as soon as they are released by the vendor. The potential for unauthorized access to health data necessitates a swift response to any security updates issued by OPPO.