Impact
The vulnerability arises from NuBrowser's lack of a strict whitelist for the protocol in the S.browser_fallback_url field of intent:// URLs. This omission allows an attacker to embed a javascript: URL inside a 302 redirect that triggers the browser's intent handling. When the redirect is processed, the embedded javascript executes with the privileges of the originating website, creating a universal cross‑site scripting (UXSS) flaw that can run arbitrary code in the context of any origin visited by the user. This flaw is a classic example of the OWASP CWE‑79: Cross‑Site Scripting.
Affected Systems
Affected products include the ZTE NebulaOS operating system, specifically the NuBrowser web component. No version‑specific details were disclosed, so any installation of NebulaOS that contains the affected NuBrowser implementation is potentially vulnerable. Existing official references point to a support bulletin but do not list a fixed version, indicating the need for vendor updates.
Risk and Exploitability
The CVSS score of 6.5 categorizes the flaw as medium severity, and the EPSS score is currently unavailable, suggesting limited information on real‑world exploitation. Although the vulnerability is not listed in the CISA KEV catalog, it can be triggered by a malicious link or an attacker‑controlled web page that initiates an intent:// URL containing a 302 redirect to a javascript: URL. The attack requires user interaction through the browser but does not need elevated privileges, making it relatively straightforward to exploit. Security teams should treat this as a moderate‑to‑high risk that warrants prompt mitigation.
OpenCVE Enrichment