CVE-2026-78997
UCWeb · UC Browser for Android
UC Browser for Android (13.7.8.1314) contains a Universal Cross-Site Scripting (UXSS) flaw allowing unauthenticated attackers to execute arbitrary JavaScript in the context of any origin.
Executive summary
A critical Universal Cross-Site Scripting vulnerability in UC Browser for Android allows unauthenticated attackers to execute malicious code within any website context, posing a severe risk to user data.
Vulnerability
The browser contains a Universal Cross-Site Scripting vulnerability in its internal JavaScript bridge. An unauthenticated attacker can leverage a reflected XSS on a UC-owned domain to register a deferred callback, which executes arbitrary code when a victim navigates to a target site.
Business impact
Successful exploitation allows an attacker to bypass the Same-Origin Policy, leading to the potential theft of session cookies, credentials, and sensitive information from any website visited by the user. Given the CVSS score of 9.3, this vulnerability represents a critical risk to user privacy and organizational security, as it effectively grants attackers the ability to perform actions on behalf of the victim across the entire web.
Remediation
Immediate Action: Users should immediately stop using UC Browser version 13.7.8.1314 and switch to a secure, updated alternative until the vendor releases a patched version.
Proactive Monitoring: Security teams should monitor mobile device management logs for the presence of this specific browser package and enforce policies to restrict its use on corporate-managed devices.
Compensating Controls: While browser-level flaws are difficult to mitigate via network controls, organizations should ensure that all internal web applications implement strict Content Security Policy (CSP) headers to limit the impact of potential client-side script injection.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the research write-ups referenced in the CVE record.
Analyst recommendation
The critical nature of this vulnerability, combined with the availability of a public proof-of-concept, necessitates immediate action. Organizations must prioritize the removal of the affected browser version from all mobile endpoints to prevent potential data compromise and unauthorized account access.
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.3 (3.1)
- Analyst report written