Same Origin Policy Bypass in Android WebView by Google
CVE-2014-6041

Currently unrated

Key Information:

Vendor
Google
Vendor
CVE Published:
2 September 2014

Summary

The Android WebView in versions prior to 4.4 contains a vulnerability that allows remote attackers to bypass the Same Origin Policy. This exploit can be executed by crafting a specific attribute containing a null character, which can lead to unauthorized actions or data exposure. The issue primarily affects users of the Android Browser application version 4.2.1 and various third-party web browsers relying on WebView. Awareness and timely updates are crucial for maintaining the security integrity of Android devices.

References

EPSS Score

70% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.