CVE-2014-6041
Android Browser RCE Through Google Play Store XFO
Title source: metasploitDescription
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser.
Exploits (3)
metasploit
WORKING POC
by Rafay Baloch, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/android/google_play_store_uxss_xframe_rce.rb
metasploit
WORKING POC
by Rafay Baloch, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/android_stock_browser_uxss.rb
metasploit
WORKING POC
by Rafay Baloch, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/android_object_tag_webview_uxss.rb
References (8)
Scores
EPSS
0.7756
EPSS Percentile
99.0%
Details
CWE
CWE-264
Status
published
Products (1)
google/android_browser
4.2.1
Published
Sep 02, 2014
Tracked Since
Feb 18, 2026