NuBrowser Universal Cross-Site Scripting Vulnerability in ZTE Products
CVE-2026-86550

6.5MEDIUM

Key Information:

Vendor

Zte

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86550?

The vulnerability in NuBrowser originates from a lack of proper protocol whitelist validation for the S.browser_fallback_url field when handling intent:// links. This oversight provides an avenue for attackers to manipulate request redirections using 302 responses, leading to the potential injection of malicious javascript: URLs. Such exploitation can result in a universal cross-site scripting (UXSS) vulnerability, where scripts can be executed in the context of any website, posing significant security risks to users. Organizations utilizing NuBrowser should review their implementations and apply necessary mitigations to prevent unauthorized script execution.

Affected Version(s)

NebulaOS Versions prior to Browser V1.6.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Omri Inbar
.