Ucweb develops a family of mobile browsers and web clients that achieved significant user reach across consumer markets. The recurring vulnerability pattern centers on information-handling flaws—particularly cleartext transmission and storage of sensitive data, UI misrepresentation, and frame-handling issues—that reflect the security challenges inherent in client-side web software with broad deployment. Current severity, exploitation status, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ucweb over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1478HIGH Unspecified vulnerability in the UCMobile BloveStorm (com.blovestorm) application 2.2.0 and 3.2.1 for Android has unknown impact and attack vectors. | Mar 14, 2012 | 10.0 | 30 | NO | NO |
CVE-2017-20041MEDIUM A vulnerability was found in Ucweb UC Browser 11.2.5.932. It has been classified as critical. Affected is an unknown function of the component HTML Handler. The manipulation of the | Jun 13, 2022 | 6.5 | 23 | NO | NO |
CVE-2019-10251MEDIUM The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PDF and Microsoft Office files (related to libpicsel), which a | Mar 28, 2019 | 5.9 | 20 | NO | NO |
CVE-2019-10250MEDIUM UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks. | Mar 28, 2019 | 5.9 | 20 | NO | NO |
CVE-2020-7364MEDIUM User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as pres | Oct 20, 2020 | 4.3 | 18 | NO | NO |
CVE-2014-6691MEDIUM The UC Browser HD (aka com.uc.browser.hd) application 3.3.1.469 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof s | Sep 23, 2014 | 5.4 | 18 | NO | NO |
UCWeb UC 12.12.3.1219 through 12.12.3.1226 uses cleartext HTTP, and thus man-in-the-middle attackers can discover visited URLs. | Aug 14, 2021 | 3.7 | 17 | NO | NO |
CVE-2020-7363MEDIUM User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as pres | Oct 20, 2020 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ucweb.
Media articles that mention a CVE ID that affects a product developed by Ucweb — matched by CVE ID, not by vendor name.