CVE-2026-78997 Details
Description
UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.
A Universal Cross-Site Scripting vulnerability has been identified in UC Browser for Android, specifically in version 13.7.8.1314. This vulnerability allows an attacker to execute arbitrary JavaScript in the context of any origin, effectively bypassing the Same-Origin Policy. The issue arises from insufficient origin validation in the browser's internal callback mechanism, which is exploited by leveraging a reflected Cross-Site Scripting vulnerability on a whitelisted vendor-owned domain. This exploitation interacts with privileged browser interfaces, enabling unauthorized actions on behalf of the user.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/OmriInbar-Novee/9fd65fe08c1b1cff6a19350e44425de2 | CISA-ADP | ExploitTechnical Analysis |
| https://gist.github.com/OmriInbar-Novee/9fd65fe08c1b1cff6a19350e44425de2 | [email protected] | ExploitTechnical Analysis |
| https://gist.github.com/OmriInbar-Novee/ef7a92db148b2eb1ab0aa7b99a565c4c | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| UC Browser | 13.7.8.1314 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion