The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T12:03:02.324Z
Reserved: 2014-09-01T00:00:00
Link: CVE-2014-6041
No data.
Status : Deferred
Published: 2014-09-02T10:55:04.730
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-6041
No data.
OpenCVE Enrichment
No data.
Weaknesses