CVE-2026-78997
Deferred Deferred - Pending Action

UC Browser Android Universal XSS via JavaScript Bridge

Vulnerability report for CVE-2026-78997, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: MITRE

Description

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ucweb uc_browser 13.7.8.1314

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Universal Cross-Site Scripting (UXSS) vulnerability in UC Browser for Android version 13.7.8.1314. It allows attackers to execute arbitrary JavaScript in the context of any website by exploiting a chain of issues including a reflected XSS on a whitelisted domain, improper storage of JavaScript callbacks, and lack of URL validation in the JavaScript execution handler. The attack bypasses the Same-Origin Policy entirely.

Detection Guidance

Detecting this vulnerability requires checking if UC Browser for Android version 13.7.8.1314 is installed on devices. Inspect installed applications on Android devices using adb shell pm list packages | grep ucweb or manually check the app version in settings. Monitor network traffic for suspicious activity involving UC Browser domains like mtmsg.uc.cn.

Impact Analysis

An attacker could exploit this to steal sensitive data like cookies, session tokens, and localStorage. This enables session hijacking, credential theft, DOM manipulation, and full account takeovers across any website. Users could lose control of their accounts or have their personal information compromised.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's safeguards for protected health information. Organizations using affected UC Browser versions may face compliance breaches, legal liabilities, and reputational damage due to potential data breaches.

Mitigation Strategies

Immediately uninstall UC Browser for Android version 13.7.8.1314 from all devices. Update to the latest version if available. Block network access to UC Browser domains like mtmsg.uc.cn at the firewall level. Educate users to avoid clicking untrusted links.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78997. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart