HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-35643 — OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vu...

·Source: NIST NVD

Updated:

Executive Summary

OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context.

Analysis

OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context. CVSS Score: 8.8. Published: 2026-04-10T17:17:04.887.

Indicators of Compromise (1)

CVE (1)
CVE-2026-35643
Source Attribution

Originally published by NIST NVD on Apr 10, 2026. Verified by: NIST.

Related Threats