Open Handset Alliance Android Browser Sandbox Security Bypass Vulnerability
BID:48954
Info
Open Handset Alliance Android Browser Sandbox Security Bypass Vulnerability
| Bugtraq ID: | 48954 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-2357 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 02 2011 12:00AM |
| Updated: | Sep 20 2011 10:10PM |
| Credit: | Roee Hay and Yair Amit |
| Vulnerable: |
Open Handset Alliance Android 3.1 Open Handset Alliance Android 2.3.4 MoboTap Inc Dolphin Browser HD 6.0 |
| Not Vulnerable: |
Open Handset Alliance Android 2.3.5 Open Handset Alliance Android 3.2 MoboTap Inc Dolphin Browser HD 6.1 |
Discussion
Open Handset Alliance Android Browser Sandbox Security Bypass Vulnerability
Open Handset Alliance Android is prone to a vulnerability that may allow a bypass of the browser sandbox.
Successful exploits will allow attackers to execute arbitrary script code within the context of an arbitrary domain.
Android 2.3.4 and 3.1 are vulnerable; prior versions may also be affected.
Open Handset Alliance Android is prone to a vulnerability that may allow a bypass of the browser sandbox.
Successful exploits will allow attackers to execute arbitrary script code within the context of an arbitrary domain.
Android 2.3.4 and 3.1 are vulnerable; prior versions may also be affected.
Exploit / POC
Open Handset Alliance Android Browser Sandbox Security Bypass Vulnerability
An attacker must trick a victim into installing a malicious application to exploit this issue.
The following example JavaScript is available:
An attacker must trick a victim into installing a malicious application to exploit this issue.
The following example JavaScript is available:
Solution / Fix
Open Handset Alliance Android Browser Sandbox Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Open Handset Alliance Android Browser Sandbox Security Bypass Vulnerability
References:
References:
- Android Browser Cross-Application Scripting (CVE-2011-2357) (Roee Hay)
- Android Browser Cross-Application Scripting CVE-2011-2357 (IBM Rational Application Security Research Group)
- Android Homepage (Google)
- Dolphin Browser HD Cross-Application Scripting (Roee Hay)
- Dolphin Browser HD Cross-Application Scripting (IBM Rational Application Security Research Group)
- Dolphin Browser HD Cross-Application Scripting (Roee Hay)