{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ucweb/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ucweb:uc_browser:*:*:*:*:*:android:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-78997"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["UC Browser (\u003c= 13.7.8.1314)"],"_cs_severities":["high"],"_cs_tags":["uxss","web-vulnerability","mobile-security"],"_cs_type":"advisory","_cs_vendors":["UCWeb"],"content_html":"\u003cp\u003eCVE-2026-78997 is a high-severity Universal Cross-Site Scripting (UXSS) vulnerability discovered in UC Browser for Android (version 13.7.8.1314 and likely earlier). The flaw exists within the application's privileged \u003ccode\u003eucapi\u003c/code\u003e JavaScript bridge, specifically related to how the \u003ccode\u003eaccount.openLoginWindow\u003c/code\u003e API handles login callbacks. Attackers can leverage a reflected XSS vulnerability on the whitelisted domain \u003ccode\u003emtmsg.uc.cn\u003c/code\u003e to register malicious JavaScript as a callback in native memory. Due to an implementation error where the callback is stored with an empty URL guard, it persists across page navigations. When a user interacts with the native login dialog and subsequently dismisses it, the browser executes the stored callback via \u003ccode\u003eWebView.evaluateJavascript()\u003c/code\u003e within the origin of the currently loaded page. This mechanism effectively allows an attacker to execute arbitrary code within the context of any destination website, bypassing the browser's Same-Origin Policy.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious URL targeting the reflected XSS parameter on the bridge-whitelisted domain \u003ccode\u003emtmsg.uc.cn\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe malicious URL triggers the \u003ccode\u003eaccount.openLoginWindow\u003c/code\u003e bridge API within the UC Browser environment.\u003c/li\u003e\n\u003cli\u003eThe attacker-supplied JavaScript payload is stored in the application's native memory as a callback.\u003c/li\u003e\n\u003cli\u003eThe application navigates to a victim website (e.g., a banking site or webmail) chosen by the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker lures the user into opening the native login dialog provided by the \u003ccode\u003eucapi\u003c/code\u003e bridge.\u003c/li\u003e\n\u003cli\u003eThe user dismisses the dialog (e.g., presses the 'X' button or taps outside the window).\u003c/li\u003e\n\u003cli\u003eThe application dispatches the stored callback, which executes the malicious JavaScript payload.\u003c/li\u003e\n\u003cli\u003eThe payload runs in the origin context of the victim website, facilitating data theft or unauthorized actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript in the context of any website visited by the user. This grants an attacker the ability to steal sensitive session cookies, tokens, or personal information, as well as perform actions on behalf of the user, such as modifying account settings or initiating fraudulent transactions. This vulnerability is particularly dangerous for users of mobile banking or sensitive web-based services on affected versions of UC Browser.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate UC Browser for Android to the latest patched version available from the vendor.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately available, restrict the use of the browser for accessing sensitive web services.\u003c/li\u003e\n\u003cli\u003eMonitor device-level logs for signs of suspicious \u003ccode\u003eWebView\u003c/code\u003e activity if using advanced mobile threat defense tooling.\u003c/li\u003e\n\u003cli\u003eEducate users to avoid clicking suspicious links that may redirect to \u003ccode\u003emtmsg.uc.cn\u003c/code\u003e while using the browser.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-11T12:31:03Z","date_published":"2026-09-11T12:31:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-78997/","summary":"A Universal Cross-Site Scripting (UXSS) vulnerability, CVE-2026-78997, allows attackers to bypass the Same-Origin Policy in UC Browser for Android by exploiting a flaw in the ucapi login callback mechanism.","title":"Universal XSS in UC Browser for Android via ucapi Bridge","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-78997/"}],"language":"en","title":"CraftedSignal Threat Feed - UCWeb","version":"https://jsonfeed.org/version/1.1"}