PT-2014-2851 · Google · Android
Tamami Eguchi
·
Publicado
2014-03-03
·
Atualizado
2014-03-10
·
CVE-2013-4710
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions 3.0 through 4.1.x
Description
The issue is related to the improper implementation of the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page. This can be achieved by using the
WebView.addJavascriptInterface method.Recommendations
For Android versions 3.0 through 4.1.x, consider disabling the
WebView.addJavascriptInterface method as a temporary workaround until a patch is available. Restrict access to the WebView class to minimize the risk of exploitation.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android