|
Google Chrome for Android contains a flaw that allows a universal cross-site scripting (UXSS) attack. This flaw exists because the com.google.android.apps.chrome.SimpleChromeActivity class does not validate input passed via the current tab before returning it to the user. A malicious application can exploit this to execute arbitrary script code in a user's browser within the trust relationship between the browser and a web server.
|