Same Origin Policy Bypass in Android WebView by Google
CVE-2014-6041
Currently unrated
Summary
The Android WebView in versions prior to 4.4 contains a vulnerability that allows remote attackers to bypass the Same Origin Policy. This exploit can be executed by crafting a specific attribute containing a null character, which can lead to unauthorized actions or data exposure. The issue primarily affects users of the Android Browser application version 4.2.1 and various third-party web browsers relying on WebView. Awareness and timely updates are crucial for maintaining the security integrity of Android devices.
References
EPSS Score
70% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved