4.3
CVSSv2

CVE-2011-2357

Published: 12/08/2011 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 3.1

google android 2.3.4

Exploits

source: wwwsecurityfocuscom/bid/48954/info Open Handset Alliance Android is prone to a vulnerability that may allow a bypass of the browser sandbox Successful exploits will allow attackers to execute arbitrary script code within the context of an arbitrary domain Android 234 and 31 are vulnerable; prior versions may also be affecte ...
A 3rd party application may exploit Android's Browser URL loading process in order to inject JavaScript code into an arbitrary domain thus break Android's sandboxing Versions 234 and 31 have been found vulnerable ...
Dolphin Browser HD versions prior to 610 suffer from a cross applications scripting vulnerability ...

Recent Articles

Who Wants Ice Cream?
Securelist • Tim Armstrong • 02 Nov 2011

Google has recently announced the forthcoming availability of Ice Cream Sandwich, Android 4.0. In such a short time, Android has seemingly come so far. I’d like to stop and take a look at the security improvements and additions featured in this release. Google’s Android debuted in November 2007 and with its steady rise in popularity we also saw researchers begin to search for holes. A number of vulnerabilities have been found from root exploits like Rage Against the Cage to cross application...