CVE-2014-6041

Android Browser RCE Through Google Play Store XFO

Title source: metasploit

Description

The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser.

Exploits (3)

metasploit WORKING POC
by Rafay Baloch, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/android/google_play_store_uxss_xframe_rce.rb
metasploit WORKING POC
by Rafay Baloch, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/android_stock_browser_uxss.rb
metasploit WORKING POC
by Rafay Baloch, joev · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/android_object_tag_webview_uxss.rb

Scores

EPSS 0.7756
EPSS Percentile 99.0%

Details

CWE
CWE-264
Status published
Products (1)
google/android_browser 4.2.1
Published Sep 02, 2014
Tracked Since Feb 18, 2026