PT-2020-4018 · Google+1 · Android Webview+1

Published

2020-09-08

·

Updated

2023-12-31

·

CVE-2020-16873

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Xamarin.Forms versions prior to 83.0.4103.106
Description: A spoofing issue exists due to the default settings on Android WebView, allowing an attacker to execute arbitrary Javascript code on a target system. The attack requires the targeted user to browse to a malicious website or a website serving malicious code through Xamarin.Forms. The security update prevents malicious Javascript from running in the WebView.
Recommendations: For versions prior to 83.0.4103.106, update to version 83.0.4103.106 or later to address the spoofing vulnerability. As a temporary workaround, consider restricting access to the WebView component to minimize the risk of exploitation. Avoid using the Xamarin.Forms component to browse to untrusted websites until the issue is resolved.

Fix

Spoofing

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2020-04418
CVE-2020-16873

Affected Products

Android Webview
Xamarin.Forms