CVE-2026-3671 | Freedom Factory dGEN1 up to 20260221 org.ethereumphone.walletmanager.testing123 TokenBalanceContentProvider improper authorization
A vulnerability was found in Freedom Factory dGEN1 up to 20260221. It has been declared as problematic. Affected by this vulnerability is the function TokenBalanceContentProvider of the component org.ethereumphone.walletmanager.testing123. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-3671. The attack requires local access. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.