SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-78997

CRITICAL · CVSS 9.3 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

UC Browser for Android version 13.7.8.1314 is vulnerable to a Universal Cross-Site Scripting (XSS) flaw that enables attackers to execute arbitrary JavaScript in the context of any origin. By hosting a specially crafted URL, an attacker can leverage the browser's internal JavaScript bridge to run malicious code on a victim site after a login dialog is dismissed. Organizations using this browser should prioritize remediation to protect users from potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78997
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%
Android Java

Original NVD Description

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.