Back to search
CVE-2012-6636
Published: Mar 3, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.cs.utexas.edu/~shmat/shmat_ndss14nofrak.pdf
x_refsource_MISC
http://www.internetsociety.org/ndss2014/programme#session3
x_refsource_MISC
[oss-security] 20140207 Re: CVE request: multiple issues in Apache Cordova/PhoneGap
mailing-list
x_refsource_MLIST
https://support.lenovo.com/us/en/product_security/len_6421
x_refsource_CONFIRM
http://50.56.33.56/blog/?p=314
x_refsource_MISC
JVN#62161191
third-party-advisory
x_refsource_JVN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now