ZeroHour

CVE-2026-78997

mass

Universal Cross-Site Scripting (UXSS) in UC Browser for Android 13.7.8.1314

CVSS 3.1
9.3 critical
EPSS
<1%p20
Published
()
Modified
AI analysis

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting (UXSS) flaw, CWE-79, that lets attacker-controlled JavaScript execute in the context of any website origin, not just the page the attacker controls. To trigger it, an attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that uses the browser's internal JavaScript bridge to register a deferred callback, navigates the tab to the victim site, and fires the callback when a login dialog is dismissed. Successful exploitation lets the attacker read and modify page content, steal cookies, session tokens, or credentials, and act as the user on any site visited in that tab, consistent with the CVSS 3.1 score of 9.3 (critical, scope changed, high confidentiality and integrity impact). Any user of the affected Android browser is exposed, and the attack requires only that the user open a crafted link, with no privileges or special network position needed. There is no known public proof-of-concept, no CISA KEV listing, and no reported in-the-wild exploitation; EPSS estimates only a 0.2% probability of exploitation in the next 30 days (5th percentile).

What to do: Check whether your environment or users have UC Browser for Android installed and note the version (13.7.8.1314 is confirmed affected); update via Google Play when a patched build is published, since no fixed version is documented in the available data. Until a fix is available, prefer another browser for high-value accounts and avoid tapping links pointing to UC-owned domains or dismissing unexpected login dialogs while using UC Browser. Defenders should also watch for vendor advisories, as the low EPSS and absence of a public PoC indicate exploitation risk is currently low but may change once details circulate.

Affected
UCWeb (Alibaba) UC Browser for Android (com.UCMobile.intl)13.7.8.1314 confirmed affected; the full affected version range is not specified in the advisory data
Estimated exposure
masstens to hundreds of millions of users (UC Browser has hundreds of millions of Android installs) — UC Browser for Android (com.UCMobile.intl) has historically been among the most-installed Android browsers on Google Play with hundreds of millions of downloads, concentrated in India and Southeast Asia, so users on affected builds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.