Loading HuntDB...

GHSA-36j3-xxf7-4pqg

GitHub Security Advisory

Android WebView Universal Cross-site Scripting

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A universal cross-site scripting (UXSS) vulnerability, CVE-2020-6506 (https://crbug.com/1083819), has been identified in the Android WebView system component, which allows cross-origin iframes to execute arbitrary JavaScript in the top-level document. This vulnerability affects React Native apps which use a `react-native-webview` that allows navigation to arbitrary URLs, and when that app runs on systems with an Android WebView version prior to 83.0.4103.106.

## Pending mitigation

Ensure users update their Android WebView system component via the Google Play Store to 83.0.4103.106 or higher to avoid this UXSS. 'react-native-webview' is working on a mitigation but it could take some time.

### References

https://alesandroortiz.com/articles/uxss-android-webview-cve-2020-6506/

Affected Packages

npm react-native-webview
Affected versions: 0 (fixed in 11.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-36j3-xxf7-4pqg
Published
October 2, 2020 4:22 PM
Last Modified
August 3, 2022 11:40 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
react-native-webview
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.