EIP-2026-100061

PRE-CVE

Australian Education App - Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100061. PoCs published by intern0t.

AI-analyzed exploit summary This exploit demonstrates a Remote Code Execution (RCE) vulnerability in the Australian Education App (v6) due to the use of `addJavascriptInterface()` in an older Android API version. An attacker can register the domain `tsearch.com.au` and serve malicious JavaScript to execute arbitrary commands on the victim's device.

Description

Australian Education App - Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by intern0t · textremoteandroid
https://www.exploit-db.com/exploits/42289

This exploit demonstrates a Remote Code Execution (RCE) vulnerability in the Australian Education App (v6) due to the use of `addJavascriptInterface()` in an older Android API version. An attacker can register the domain `tsearch.com.au` and serve malicious JavaScript to execute arbitrary commands on the victim's device.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Australian Education App v6
No auth needed
Prerequisites: Domain registration of `tsearch.com.au` · Victim must open the vulnerable app
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026