CVE-2014-6041 is a critical Same Origin Policy (SOP) bypass vulnerability in the Android WebView component, affecting the default AOSP browser on Android versions prior to 4.4. The vulnerability arises from insufficient validation of the JavaScript scheme in the HTMLPlugInImageElement::allowedToLoadFrameURL function, allowing attackers to inject a crafted attribute containing a null byte (\u0000) in a window.open call. This enables execution of JavaScript in the context of another domain, violating browser security boundaries. Attackers can exploit this flaw to steal cookies, session tokens, and page content from other domains, and in some cases, read local files such as the sqlite cookie database. The vulnerability was widely exploitable on a large number of Android devices, especially those running outdated browsers based on WebKit.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module that exploits a Universal Cross-Site Scripting (UXSS) vulnerability (CVE-2014-6041) in Android's open source stock browser (AOSP) before version 4.4 and Android apps embedding WebView on <4.4. The module acts as a malicious web server. When a vulnerable browser visits the attacker's server, the module serves obfuscated JavaScript that uses the <object> tag to load attacker-specified target URLs. The script bypasses the Same-Origin Policy, allowing it to steal cookies and page contents from those URLs. Stolen data is exfiltrated back to the attacker's server via a POST request. The module allows customization of target URLs, custom JavaScript, and remote JavaScript injection. The exploit is operational and can be used to demonstrate or perform real data theft from affected browsers. The only code file is a Ruby Metasploit module, which generates and serves the malicious JavaScript payload.
This repository contains a single Metasploit auxiliary module targeting Android devices vulnerable to CVE-2014-6041 (UXSS in the AOSP Browser <4.4) and a Google Play Store web interface X-Frame-Options (XFO) bypass. The module sets up a malicious web server that serves crafted HTML/JavaScript. When a victim using a vulnerable browser visits the server and is logged into Google, the exploit chains the UXSS and XFO bypass to inject scripts into the Google Play Store, remotely installing and launching an arbitrary app (specified by the attacker) on the victim's device. The module allows configuration of the app package and activity to launch, and includes options to hide the exploit iframe and check for Google login status. The main attack vectors are browser-based (drive-by via malicious web page) and network-based (interaction with Google Play and Google Accounts endpoints). The code is operational and leverages both Ruby (Metasploit module) and JavaScript (payload).
This repository contains a single Metasploit auxiliary module targeting a Universal Cross-Site Scripting (UXSS) vulnerability (CVE-2014-6041) in the Android AOSP stock browser and WebView components prior to version 4.4. The module sets up a malicious HTTP server that serves specially crafted HTML/JavaScript to exploit the vulnerability when visited by a victim using a vulnerable browser. Upon successful exploitation, the module can exfiltrate cookies and page contents from specified target URLs, and optionally execute arbitrary JavaScript in the context of those URLs (via the CUSTOM_JS or REMOTE_JS options). The module supports bypassing X-Frame-Options protections using a popup technique, which requires user interaction. All configuration is handled via Metasploit options, and exfiltrated data is stored using Metasploit's loot system. The code is written in Ruby (for the Metasploit module) and generates JavaScript payloads for the browser. The main entry point is the Metasploit module file itself.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.