CVE-2026-102670: Joyland Joyland.ai

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.

Affected products

Published 2026-10-01. Last modified 2026-10-01.