PT-2014-2851 · Google · Android
Tamami Eguchi
·
Published
2014-03-03
·
Updated
2014-03-10
·
CVE-2013-4710
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions 3.0 through 4.1.x
Description
The issue is related to the improper implementation of the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page. This can be achieved by using the
WebView.addJavascriptInterface method.Recommendations
For Android versions 3.0 through 4.1.x, consider disabling the
WebView.addJavascriptInterface method as a temporary workaround until a patch is available. Restrict access to the WebView class to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android