← Back

CVE-2012-6636

nvd nist
Published: Mar 3, 2014Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection API within crafted JavaScript code that is loaded into the WebView component in an application targeted to API level 16 or earlier, a related issue to CVE-2013-4710.

Affected (16)

Products: Google: Android Api
1 product
Android Api
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Google
Up to 16.0
Version 1.0
Version 10.0
Version 11.0
Version 12.0
Version 13.0
Version 14.0
Version 15.0
Version 2.0
Version 3.0
Version 4.0
Version 5.0
Version 6.0
Version 7.0
Version 8.0
Version 9.0

Related CWEs

References (16)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.