Impact
The UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross‑Site Scripting vulnerability that lets an attacker execute arbitrary JavaScript within the context of any origin. The flaw is a reflected XSS that triggers when a login dialog is dismissed, allowing malicious code to run on victim websites. Because it runs with the privileges of the target page, the vulnerability effectively permits remote code execution.
Affected Systems
Only the UC Browser for Android, identified by package name com.UCMobile.intl version 13.7.8.1314, is known to be affected. No other vendors or products are listed as impacted at this time.
Risk and Exploitability
The CVSS score of 9.3 indicates high severity, but the EPSS score of < 1% suggests a very low probability of active exploitation. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited current exploitation activity. Exploitation requires an attacker to host a malicious URL on a UC‑owned domain, embed a reflected XSS payload that registers a deferred callback, navigate the victim’s tab to a chosen website, and inject attacker‑controlled code once a login dialog is dismissed. This attack path is feasible for users who click the link while the vulnerable browser is running.
OpenCVE Enrichment