CVE-2013-4710 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 43.4% (pctl 99)
Patch early
A public exploit exists.
Description
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 43.36% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-03-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| android |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Android Browser and WebView addJavascriptInterface - Code Execution (Metasploit) | 2014-02-07 |
| exploit-db | Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit) | 2012-12-21 |
References
- http://50.56.33.56/blog/?p=314
- http://emobile.jp/products/sh/a01sh/systemsoftware.html
- http://jvn.jp/en/jp/JVN53768697/113349/index.html
- http://jvn.jp/en/jp/JVN53768697/397327/index.html
- http://jvn.jp/en/jp/JVN53768697/995293/index.html
- http://jvn.jp/en/jp/JVN53768697/995312/index.html
- http://jvn.jp/en/jp/JVN53768697/995417/index.html
- http://jvn.jp/en/jp/JVN53768697/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000111
- http://openwall.com/lists/oss-security/2014/02/18/11
- http://50.56.33.56/blog/?p=314
- http://emobile.jp/products/sh/a01sh/systemsoftware.html
- http://jvn.jp/en/jp/JVN53768697/113349/index.html
- http://jvn.jp/en/jp/JVN53768697/397327/index.html
- http://jvn.jp/en/jp/JVN53768697/995293/index.html
- http://jvn.jp/en/jp/JVN53768697/995312/index.html
- http://jvn.jp/en/jp/JVN53768697/995417/index.html
- http://jvn.jp/en/jp/JVN53768697/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000111
- http://openwall.com/lists/oss-security/2014/02/18/11
→ the Explorer · watch your stack · NVD