Description
NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Universal Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from NuBrowser's lack of a strict whitelist for the protocol in the S.browser_fallback_url field of intent:// URLs. This omission allows an attacker to embed a javascript: URL inside a 302 redirect that triggers the browser's intent handling. When the redirect is processed, the embedded javascript executes with the privileges of the originating website, creating a universal cross‑site scripting (UXSS) flaw that can run arbitrary code in the context of any origin visited by the user. This flaw is a classic example of the OWASP CWE‑79: Cross‑Site Scripting.

Affected Systems

Affected products include the ZTE NebulaOS operating system, specifically the NuBrowser web component. No version‑specific details were disclosed, so any installation of NebulaOS that contains the affected NuBrowser implementation is potentially vulnerable. Existing official references point to a support bulletin but do not list a fixed version, indicating the need for vendor updates.

Risk and Exploitability

The CVSS score of 6.5 categorizes the flaw as medium severity, and the EPSS score is currently unavailable, suggesting limited information on real‑world exploitation. Although the vulnerability is not listed in the CISA KEV catalog, it can be triggered by a malicious link or an attacker‑controlled web page that initiates an intent:// URL containing a 302 redirect to a javascript: URL. The attack requires user interaction through the browser but does not need elevated privileges, making it relatively straightforward to exploit. Security teams should treat this as a moderate‑to‑high risk that warrants prompt mitigation.

Generated by OpenCVE AI on September 8, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ZTE NebulaOS to a release that includes a corrected NuBrowser implementation with protocol whitelist enforcement for intent:// URLs.
  • Apply a network‑level or browser‑based policy that blocks or verifies intent:// URLs and disallows javascript: schemes in fallback URLs.
  • Configure the browser or the device to disable or restrict use of 302 redirects that target intent:// URLs, or to filter them before they reach the intent handler.

Generated by OpenCVE AI on September 8, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte nebulaos
Vendors & Products Zte
Zte nebulaos

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.
Title UXSS vulnerability in ZTE browser products
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2026-09-08T12:24:02.546Z

Reserved: 2026-09-08T02:55:52.365Z

Link: CVE-2026-86550

cve-icon Vulnrichment

Updated: 2026-09-08T12:23:58.840Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T09:18:21.747

Modified: 2026-09-09T15:52:04.827

Link: CVE-2026-86550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:35:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')