EcoOnline EHS for Android version 0.2.499 contains an AndroidManifest.xml component exposure issue. An improperly exposed application component may be remotely invoked by an attacker, allowing disclosure of sensitive information and arbitrary code execution in the affected Android application context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small public advisory and benign proof-of-concept for CVE-2026-26897 affecting EcoOnline EHS for Android (package com.airsweb.v10). It contains three files: a top-level README with the vulnerability write-up, poc/README.md with reproduction steps, and poc/redirect-proof.html containing the only executable code. The issue is a deep-link validation bypass in the app’s exported MainActivity: any ehs-app:// URI is accepted, the scheme is naively rewritten from ehs-app: to https:, and the resulting URL is passed to WebView.loadUrl() without applying the app’s internal host allow-list. The exploit capability is therefore an arbitrary-origin WebView load/open redirect inside the trusted mobile app, primarily enabling phishing and UI spoofing after user interaction. The included HTML PoC is intentionally non-malicious: it performs no credential capture, storage, or network exfiltration, and only displays local runtime context to prove that attacker-controlled content can be rendered inside the app. This is a genuine exploit PoC rather than a detection script, but it is limited in scope and maturity because it demonstrates the vulnerability without weaponized payload delivery.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.