CVE detail
CVE-2014-6041
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- How to remotely install malicious apps on Android devicesSecurity Affairs
Security researchers discovered how to install and launch malicious applications remotely on Android devices exploiting two flaws. Security researchers have uncovered a couple of vulnerabilities in the Google Play Store that could allow cyber criminals to install and launch malicious apps remotely on Android mobile devices. The expert Tod Beardsley, technical lead for the Metasploit […]
newssecurityaffairs.comFeb 13, 2015, 7:11 AM Security Experts at Trend Micro discovered a series of hacking attacks targeting Facebook users and exploiting the Same Origin Policy vulnerability. A serious security vulnerability affects the default web browser of the Android OS lower than 4.4, according the data provided by Google official dashboard nearly the 66% of Android devices is impacted. The security […]
newssecurityaffairs.comDec 30, 2014, 2:14 PMResearchers at Trend Micro say attackers are actively exploiting a vulnerability in Android’s WebView browser in order to compromise Facebook accounts.
newswww.securityweek.comDec 30, 2014, 2:04 AMA universal cross-site scripting (UXSS) vulnerability has been identified in the Android browser that’s installed by default on many Android smartphones, researchers reported on Thursday.
newswww.securityweek.comNov 7, 2014, 2:14 PMA Same Origin Policy (SOP) bypass vulnerability has been identified in the Android browser installed by default on versions of the operating system prior to 4.4, a researcher revealed on Thursday.
newswww.securityweek.comOct 3, 2014, 4:15 PM- Android browser flaw found to leak dataCSO Online
A security researcher has found another flaw in the Android browser that a cybercriminal could use to steal sensitive data. The latest same-origin policy (SOP) bypass vulnerability is the second discovered by researcher Rafay Baloch, who discovered the first, CVE-2014-6041, last month. The vulnerability is in how Javascript is handled by the Android function responsible […]
newswww.csoonline.comOct 3, 2014, 12:11 AM - Android Same Origin Policy flaw affects more than 70% devicesSecurity Affairs
A serious flaw vulnerability has been discovered in the default browser on a large number of Android devices that allows to bypass the Same Origin Policy. A critical flaw has been discovered in the Web browser installed by default on the majority of Android mobile devices, it has been estimated that nearly 70 percent of the […]
newssecurityaffairs.comSep 17, 2014, 7:49 PM A serious vulnerability has been discovered in the Web browser installed by default on a large number of Android devices, researchers have warned.
newswww.securityweek.comSep 16, 2014, 12:39 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-18593CVSS 2.9 · Low
A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Manage…
- CVE-2026-58556CVSS 5.1 · Medium
Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-58555CVSS 6.6 · Medium
Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-14784CVSS 5.3 · Medium
A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipul…
- CVE-2026-41974CVSS 3.6 · Low
Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-9368CVSS 5.5 · Medium
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Envir…