NuBrowser Universal Cross-Site Scripting Vulnerability in ZTE Products
CVE-2026-86550
6.5MEDIUM
What is CVE-2026-86550?
The vulnerability in NuBrowser originates from a lack of proper protocol whitelist validation for the S.browser_fallback_url field when handling intent:// links. This oversight provides an avenue for attackers to manipulate request redirections using 302 responses, leading to the potential injection of malicious javascript: URLs. Such exploitation can result in a universal cross-site scripting (UXSS) vulnerability, where scripts can be executed in the context of any website, posing significant security risks to users. Organizations utilizing NuBrowser should review their implementations and apply necessary mitigations to prevent unauthorized script execution.
Affected Version(s)
NebulaOS Versions prior to Browser V1.6.8
