RULE(RULE ID:311377)

Rule General Information
Release Date: 2015-02-24
Rule Name: Google Android Browser Same Origin Policy Bypass Vulnerability (CVE-2014-6041)
Severity:
CVE ID:
Rule Protection Details
Description: The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character.
Impact: An attacker can take advantage of the vulnerability to bypass the security policy implemented by the software administrator, and perform unauthorized actions to the target system.
Affected OS: Android
Reference: SecurityFocusBID:69548
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://android.googlesource.com/platform/external/webkit/+/7e4405a7a12750ee27325f065b9825c25b40598c