CVE-2012-6636
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods...
- Published
- Mar 3, 2014
- Updated
- Aug 6, 2024
- Assigning CNA
- mitre
- Evidence observed
- Dec 21, 2012
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:PModerate · next 30 days
- Percentile
- 98.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.
Sources
2An app demo for test android webview security issue: CVE-2012-6636
- Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit)Exploit
Metasploit · android · Dec 21, 2012
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.