CVE-2011-2357
Last modified
CVE-2011-2357 is a vulnerability of currently unknown severity. Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.. EPSS estimates a 4.61% chance of exploitation in the next 30 days.
Description
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to be opened, then loading a URI to the targeted domain into the current tab, or (2) making two startActivity function calls beginning with the targeted domain's URI followed by the malicious Javascript while the UI focus is still associated with the targeted domain.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 2.3.4 | |
| Android | 3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2357?
How severe is CVE-2011-2357?
How do I fix CVE-2011-2357?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-2350The HTML parser in Google Chrome before 12.0.742.112 does no…
- CVE-2011-2351Use-after-free vulnerability in Google Chrome before 12.0.74…
- CVE-2011-2352WebKit, as used in Apple iTunes before 10.5, allows man-in-t…
- CVE-2011-2353Use after free vulnerability in documentloader in WebKit in …6.5
- CVE-2011-2354WebKit, as used in Apple iTunes before 10.5, allows man-in-t…
- CVE-2011-2356WebKit, as used in Apple iTunes before 10.5, allows man-in-t…
- CVE-2011-2358Google Chrome before 13.0.782.107 does not ensure that exten…
- CVE-2011-2359Google Chrome before 13.0.782.107 does not properly track li…
- CVE-2011-2360Google Chrome before 13.0.782.107 does not ensure that the u…
- CVE-2011-2361The Basic Authentication dialog implementation in Google Chr…
- CVE-2011-2362Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, an…
- CVE-2011-2363Use-after-free vulnerability in the nsSVGPointList::AppendEl…
Are you affected by CVE-2011-2357?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
