CVE-2014-6041
Published on: 09/02/2014 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:25:54 PM UTC
Certain versions of Android Browser from Google contain the following vulnerability:
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser.
- CVE-2014-6041 has been assigned by
[email protected] to track the vulnerability
CVSS2 Score: 5.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Just an update from the Google side: As discussed below, any Android users on 4.... | Hacker News | news.ycombinator.com text/html |
![]() |
7e4405a7a12750ee27325f065b9825c25b40598c - platform/external/webkit - Git at Google | android.googlesource.com text/html |
![]() |
Metasploit: Major Android Bug is a Privacy Disa... | SecurityStreet | community.rapid7.com text/html |
![]() |
Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041 | Learn How To Hack - Ethical Hacking and security tips | Exploit www.rafayhackingarticles.net text/html |
![]() |
IBM X-Force Exchange | exchange.xforce.ibmcloud.com text/html |
![]() |
Major Android Bug Is a Privacy Disaster (CVE-2014-6041) | Hacker News | news.ycombinator.com text/html |
![]() |
Google Android Browser CVE-2014-6041 Same Origin Policy Security Bypass Vulnerability | cve.report (archive) text/html |
![]() |
1368e05e8875f00e8d2529fe6050d08b55ea4d87 - platform/external/webkit - Git at Google | android.googlesource.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Android Browser | 4.2.1 | All | All | All | |
Application | Android Browser | 4.2.1 | All | All | All |
- cpe:2.3:a:google:android_browser:4.2.1:*:*:*:*:android:*:*:
- cpe:2.3:a:google:android_browser:4.2.1:*:*:*:*:android:*:*:
No vendor comments have been submitted for this CVE