Skip to main content

CVE detail

CVE-2014-6041

The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser.

CVSS 5.8 · MediumBuzz score 30.0

Buzz score

Why this CVE is surfacing

Buzz score total 30.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first
  • Security researchers discovered how to install and launch malicious applications remotely on Android devices exploiting two flaws. Security researchers have uncovered a couple of vulnerabilities in the Google Play Store that could allow cyber criminals to install and launch malicious apps remotely on Android mobile devices. The expert Tod Beardsley, technical lead for the Metasploit […]

    newssecurityaffairs.comFeb 13, 2015, 7:11 AM
  • Security Experts at Trend Micro discovered a series of hacking attacks targeting Facebook users and exploiting the Same Origin Policy vulnerability. A serious security vulnerability affects the default web browser of the Android OS lower than 4.4, according the data provided by Google official dashboard nearly the 66% of Android devices is impacted. The security […]

    newssecurityaffairs.comDec 30, 2014, 2:14 PM
  • Researchers at Trend Micro say attackers are actively exploiting a vulnerability in Android’s WebView browser in order to compromise Facebook accounts.

    newswww.securityweek.comDec 30, 2014, 2:04 AM
  • A universal cross-site scripting (UXSS) vulnerability has been identified in the Android browser that’s installed by default on many Android smartphones, researchers reported on Thursday.

    newswww.securityweek.comNov 7, 2014, 2:14 PM
  • A Same Origin Policy (SOP) bypass vulnerability has been identified in the Android browser installed by default on versions of the operating system prior to 4.4, a researcher revealed on Thursday.

    newswww.securityweek.comOct 3, 2014, 4:15 PM
  • A security researcher has found another flaw in the Android browser that a cybercriminal could use to steal sensitive data. The latest same-origin policy (SOP) bypass vulnerability is the second discovered by researcher Rafay Baloch, who discovered the first, CVE-2014-6041, last month. The vulnerability is in how Javascript is handled by the Android function responsible […]

    newswww.csoonline.comOct 3, 2014, 12:11 AM
  • A serious flaw vulnerability has been discovered in the default browser on a large number of Android devices that allows to bypass the Same Origin Policy. A critical flaw has been discovered in the Web browser installed by default on the majority of Android mobile devices, it has been estimated that nearly 70 percent of the […]

    newssecurityaffairs.comSep 17, 2014, 7:49 PM
  • A serious vulnerability has been discovered in the Web browser installed by default on a large number of Android devices, researchers have warned.

    newswww.securityweek.comSep 16, 2014, 12:39 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-18593

    A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Manage…

    CVSS 2.9 · Low
    5 mentions
  • CVE-2026-58556

    Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

    CVSS 5.1 · Medium
    1 mention
  • CVE-2026-58555

    Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

    CVSS 6.6 · Medium
    2 mentions
  • CVE-2026-14784

    A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipul…

    CVSS 5.3 · Medium
    7 mentions
  • CVE-2026-41974

    Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

    CVSS 3.6 · Low
    2 mentions
  • CVE-2026-9368

    A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Envir…

    CVSS 5.5 · Medium
    4 mentions