CVE-2026-86550
Deferred Deferred - Pending Action

NuBrowser Intent URL UXSS via javascript: Injection

Vulnerability report for CVE-2026-86550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: ZTE Corporation

Description

NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-28
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NuBrowser has a flaw where it does not properly validate the S.browser_fallback_url field in intent:// URLs. Attackers can exploit this by using 302 redirects to inject javascript: URLs, leading to a universal cross-site scripting (UXSS) vulnerability. This allows malicious scripts to run in the context of any website's origin.

Impact Analysis

This vulnerability could allow attackers to execute malicious scripts in your browser when visiting compromised or malicious websites. This may lead to theft of sensitive data, session hijacking, or unauthorized actions on your behalf without your knowledge.

Mitigation Strategies

Update NuBrowser to the latest version that includes protocol whitelist validation for S.browser_fallback_url. If no update is available, disable the application until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart