CVE-2012-6636
Summary
| CVE | CVE-2012-6636 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-03-03 04:50:46 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS: 0.763380000 probability, percentile 0.989480000 (date 2026-05-05)
Problem Types: CWE-264 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Android Api | 1.0 | All | All | All | |
| Application | Android Api | 10.0 | All | All | All | |
| Application | Android Api | 11.0 | All | All | All | |
| Application | Android Api | 12.0 | All | All | All | |
| Application | Android Api | 13.0 | All | All | All | |
| Application | Android Api | 14.0 | All | All | All | |
| Application | Android Api | 15.0 | All | All | All | |
| Application | Android Api | 2.0 | All | All | All | |
| Application | Android Api | 3.0 | All | All | All | |
| Application | Android Api | 4.0 | All | All | All | |
| Application | Android Api | 5.0 | All | All | All | |
| Application | Android Api | 6.0 | All | All | All | |
| Application | Android Api | 7.0 | All | All | All | |
| Application | Android Api | 8.0 | All | All | All | |
| Application | Android Api | 9.0 | All | All | All | |
| Application | Android Api | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SHAREit for Android Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | support.lenovo.com | |
| Build.VERSION_CODES | Android Developers | af854a3a-2127-422b-91ae-364da2661108 | developer.android.com | |
| oss-security - Re: CVE request: multiple issues in Apache Cordova/PhoneGap | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| JVN#62161191: JavaFX WebEngine does not properly restrict Java method execution | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf | af854a3a-2127-422b-91ae-364da2661108 | www.cs.utexas.edu | Exploit |
| NDSS 2014 - Programme | Internet Society | af854a3a-2127-422b-91ae-364da2661108 | www.internetsociety.org | |
| Abusing WebView JavaScript Bridges | dead && end | af854a3a-2127-422b-91ae-364da2661108 | 50.56.33.56 | |
| WebView | Android Developers | af854a3a-2127-422b-91ae-364da2661108 | developer.android.com | |
| WebView | Android Developers | MITRE | developer.android.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.