Posts tagged

UC-Browser
← Back to all posts
HB

The Callback That Outlived the Page: CVE-2026-78997 — Universal XSS in UC Browser for Android

On September 8, 2026, NIST’s National Vulnerability Database published CVE-2026-78997, a Universal Cross-Site Scripting (UXSS) vulnerability in UC Browser for Android (com.UCMobile.intl, version 13.7.8.1314) — a browser with more than a billion installs on Google Play. CIS…

Tags

Account-Takeover Agentic-AI android Android Android-Adb Android-apktool Android-Avd Android-Studio Anti-Bot API-Security Authentication Automotive Backslash-Breakout Baseband Browser-Automation Browser-Fingerprinting Buffer-Overflow C2 Cache-Key-Collision Camoufox CAN-Bus CAPTCHA Chrome Command-Injection Container-Escape Cross-Site-Scripting Cudy CWE-121 CWE-122 CWE-125 CWE-1333 CWE-23 CWE-288 CWE-290 CWE-347 CWE-706 CWE-798 CWE-862 CWE-89 CWE-926 CWE-94 Data-Scraping Denial-of-Service Elixir Embedded-Systems Exploit FastGPT Firmware Frida Geolocation GooglePlay Hardware Heap-Overflow Hi-Browser html-sanitize-ex HTTP2 Hugging-Face Identity-Confusion Information Security Integer-Overflow IoT JNI JWT Lexer-Differential Linux Linux-Kernel llama-cpp LLaMA-Factory LLM LwM2M Machine-Learning MCP MediaTek Memory Disclosure MindsDB Missing-Authorization mitmproxy Mobile-Security MQTT Network-Analysis Networking OAuth OAuth2 OBD2 OIDC OpenID-Connect Out-of-Bounds Page-Cache Path-Traversal Penetration Testing pgAdmin PHP phpIPAM Playwright PostgreSQL Privilege-Escalation Prompt-Injection Python Race-Condition RCE ReDoS Reverse Engineering Reverse-Engineering Router Samsung-Bixby Samsung-Exynos Security Security-Research Session Hijacking Session-Hijacking SiYuan SMS Snapchat SNMP Speech-Recognition SQL-Injection SSD SSL-Pinning STIG-Manager Supply-Chain TECNO Tenda Traefik UC-Browser Vulnerability Web Applications Web Scraping Web-Crawling Web-Scraping Web-Security WebGPU WeChat Wi-Fi Zephyr Zero-Day