Vulnerability  ·  2026-10-02

Joyland AI app client-side security cluster: WebView injection, hard-coded GeTui push credentials, disabled TLS validation

VulnerabilityMedium impactGlobalCVE-2026-102667
A CISA-flagged cluster of client-side flaws in the Joyland AI companion app: unauthenticated JavaScript injection into the app's WebView (highest impact — device compromise if the app holds permissions), hard-coded credentials for the GeTui push service enabling spam/message spoofing at scale, and a default stance that accepts any TLS certificate, fails hostname verification, and allows cleartext HTTP — enabling chat interception by a malicious network host.
LLM companion apps are treated as trusted chat surfaces; this cluster shows the full client-side attack surface of a GenAI app — an adjacent attacker intercepting chat messages, injecting UI/instructions, and abusing push infrastructure to phish users or impersonate the AI.
CVE-2026-102667 (CVSS 8.3 v3.1 / Critical v4.0, AV:A): a network-adjacent attacker injects JavaScript into WebView-loaded content, reaching clipboard, arbitrary HTTP via Weex 'stream', and app-internal storage — full filesystem/camera/mic if previously permissioned. CVE-2026-102666: hard-coded GeTui push credentials let any unauthenticated attacker send arbitrary push notifications to any/all users. Companion CVEs cover missing hostname/TLS validation and permitted cleartext HTTP on Android 9+ (CVE-2026-102668/102669/102670/102671).
Joyland AI app (AI companion/chat application; releases carrying the embedded GeTui credentials and insecure WebView options)
Update the Joyland AI app to the patched build (rotating GeTui credentials per GHSA-pqc3-2xg8-vj54); CISA advisory VA-26-275-03 provides the full fix matrix
NVD detail
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →