CVE-2014-6041 describes a Same Origin Policy bypass vulnerability in the Android WebView component, affecting Android versions prior to 4.4, including the Android Browser and third-party web browsers. An attacker can exploit this by crafting a malicious attribute containing a null character, such as an onclick event, to execute arbitrary JavaScript. This medium-severity vulnerability (CVSS 5.8) allows for information disclosure and potential arbitrary code execution, requiring user interaction to trigger. While not listed in KEV, Metasploit modules exist, and it garnered significant community discussion and media coverage, indicating a high level of interest and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.1CPE matchmatch criteria | cpe:2.3:a:google:android_browser:4.2.1:*:*:*:*:android:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.