PT-2025-31984 · Maxthon · Maxthon3

Published

2012-12-05

·

Updated

2025-08-05

·

CVE-2012-10032

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Maxthon3 versions prior to 3.3
Description Maxthon3 versions prior to 3.3 are vulnerable to cross context scripting (XCS) through the about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw enables modification of browser configuration and execution of arbitrary code through Maxthon’s exposed DOM APIs, including maxthon.program.Program.launch() and maxthon.io.writeDataURL(). Exploitation requires user interaction, typically by visiting a malicious webpage that triggers the injection.
Recommendations Update Maxthon3 to version 3.3 or later.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05056
CVE-2012-10032

Affected Products

Maxthon3