3 ms·
From my testing, in stock android 3.1-4.1.2, the native browser has some java objects injected into it and is vulnerable, so any page on the internet could exec
by joev_ 13y ago
From my testing, in stock android 3.1-4.1.2, the native browser has some java objects injected into it and is vulnerable, so any page on the internet could execute arbitrary code. You can verify yourself by downloading the SDK and trying the metasploit module on different targets. Of course with vendor patches it's anyone's guess as to what code is on a device, so it is very possible that some vendors have patched this in their older distributions. If you want to check your device, jduck put up a test script here:
http://www.droidsec.org/tests/addjsif/ http://www.droidsec.org/tests/addjsif/
- gcb0 13y agoThanks. 2.3.3 cm7.1 is the only one safe here.