CVE-2026-35643 is an unvalidated WebView JavascriptInterface vulnerability in OpenClaw versions prior to 2026.3.22 that enables attackers to inject arbitrary instructions and execute malicious code within the Android application context by exploiting the canvas bridge through untrusted web pages. This vulnerability poses a significant risk to any Android application using the affected OpenClaw library versions. The vulnerability carries a CVSS score of 8.8 (HIGH severity) with a network-based attack vector requiring only user interaction, making it relatively easy to exploit. The attack requires no special privileges and can result in high impact across confidentiality, integrity, and availability of the affected system, allowing attackers to potentially compromise sensitive user data and application functionality. Exploitation status indicates this is not currently being actively exploited in the wild, with no known exploit code publicly available and minimal community attention to date. The FAUCET Risk Score of 52.0 and EPSS score of 0.000420 suggest lower immediate exploitation probability, though organizations should still prioritize updating to version 2026.3.22 or later to mitigate the underlying vulnerability before threat actors develop and distribute exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.22CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.22CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.