PT-2018-5557 · Google · Android

Published

2018-04-04

·

Updated

2018-05-09

·

CVE-2017-13274

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Android versions 6.0 through 8.1
Description: The issue concerns incorrect web origin determination in the getHost() function of UriTest.java. This could lead to incorrect security decisions without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations: For Android versions 6.0 through 8.1, update to a version that contains a fix for this issue to prevent incorrect security decisions.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-13274

Affected Products

Android