WebView Exploit Affects Most Android Phones
WebView Exploit Affects Most Android Phones: An exploit for a vulnerability that affects an estimated 70% of all Android devices has been added to the Metasploit open-source penetration testing framework.
The “single-click” Metasploit exploit targets a vulnerability in a WebView component that’s used by the native Android browser, although the component can also be used by other apps. Although the vulnerability has been present in some devices for nearly two years, it wasn’t publicly disclosed until 14 months ago.
“This vulnerability is kind of a huge deal,” said Tod Beardsley, the technical lead for the Metasploit Framework, in a blog post. “I’m hopeful that by publishing an E-Z-2-Use Metasploit module that exploits it, we can maybe push some vendors toward ensuring that single-click vulnerabilities like this don’t last for 93+ weeks in the wild.”
The underlying privilege-escalation flaw, which involves a Java reflection API vulnerability, exists in versions of WebView prior to 4.2, and results from that component — in some cases — allow untrusted JavaScript code to be executed. As a result, an attacker could exploit the flaw to execute arbitrary commands.