← back
CVE-2026-22077mediumCWE-346

Sensitive Information Disclosure Vulnerability Caused by Trusted Domain Bypass in OPPO Wallet

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.6epss 0.1%
exploitation probability
0.1%top 100% of all CVEs
observed exploitation
nono source reports it
OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access restrictions, which may lead to account token hijacking and sensitive information disclosure.
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/R:A/V:D/RE:L/U:Amber
Affected products
OPPO · OPPO Wallet APP