Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-6041

40
FAUCET Score

CVE-2014-6041 describes a Same Origin Policy bypass vulnerability in the Android WebView component, affecting Android versions prior to 4.4, including the Android Browser and third-party web browsers. An attacker can exploit this by crafting a malicious attribute containing a null character, such as an onclick event, to execute arbitrary JavaScript. This medium-severity vulnerability (CVSS 5.8) allows for information disclosure and potential arbitrary code execution, requiring user interaction to trigger. While not listed in KEV, Metasploit modules exist, and it garnered significant community discussion and media coverage, indicating a high level of interest and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
4.2.1CPE matchmatch criteria
cpe:2.3:a:google:android_browser:4.2.1:*:*:*:*:android:*:*

CVSS Data

CVSS version used by this source: 2.0

5.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
18.28%
Probability of exploitation in next 30 days
EPSS Percentile
96.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Metasploit: Android Open Source Platform (AOSP) Browser UXSS · Oct 4, 2014
This CVE's current EPSS score of 0.1828 is in the 97th percentile among its peer group of 19,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

android.googlesource.com / platform/external/webkit/+/1368e05e8875f00e8d2529fe6050d08b55ea4d87
android.googlesource.com / platform/external/webkit/+/7e4405a7a12750ee27325f065b9825c25b40598c
community.rapid7.com / community/metasploit/blog/2014/09/15/major-android-bug-is-a-privacy-disaster-cve-2014-6041
exchange.xforce.ibmcloud.com / vulnerabilities/95693
news.ycombinator.com / item
news.ycombinator.com / item
rafayhackingarticles.net / 2014/08/android-browser-same-origin-policy.html
Exploit
securityfocus.com / bid/69548