CVE-2020-16873 is a high-severity spoofing vulnerability in Microsoft Xamarin.Forms, specifically affecting Android WebView versions prior to 83.0.4103.106. This flaw allows an unauthenticated attacker to execute arbitrary JavaScript code if a user visits a malicious website. The vulnerability has a CVSS score of 8.8 (HIGH), indicating high impact on confidentiality, integrity, and availability, with low attack complexity requiring user interaction. While it has garnered some community discussion and media coverage, there is currently no evidence of active exploitation, nor are there public exploit modules available in Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:xamarin.forms:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.