CyberRota Analysis
AI-GeneratedThe vulnerability affects Java applications utilizing NuBrowser, which fails to validate the protocol whitelist for the S.browser_fallback_url field, allowing attackers to inject malicious javascript: URLs through 302 redirects. This leads to a universal cross-site scripting (UXSS) vulnerability, enabling unauthorized script execution within the context of arbitrary websites. Developers and security teams using Java with NuBrowser should prioritize addressing this issue to mitigate potential exploitation risks.
Original NVD Description
NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.