PT-2025-31984 · Maxthon · Maxthon3
Published
2012-12-05
·
Updated
2025-08-05
·
CVE-2012-10032
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Maxthon3 versions prior to 3.3
Description
Maxthon3 versions prior to 3.3 are vulnerable to cross context scripting (XCS) through the
about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw enables modification of browser configuration and execution of arbitrary code through Maxthon’s exposed DOM APIs, including maxthon.program.Program.launch() and maxthon.io.writeDataURL(). Exploitation requires user interaction, typically by visiting a malicious webpage that triggers the injection.Recommendations
Update Maxthon3 to version 3.3 or later.
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Maxthon3