CVE-2026-13461: Payrange

Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.

Affected products

Published 2026-07-09. Last modified 2026-07-10.