Description

MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host` attribute from `<data android:scheme="android_secret_code">` elements is rendered in HTML reports without sanitization, enabling session hijacking and account takeover. Version 4.4.5 fixes the issue.

INFO

Published Date :

2026-01-27T00:40:36.483Z

Last Modified :

2026-01-27T14:43:35.345Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-24490 vulnerability.

Vendors Products
Mobsf
  • Mobile Security Framework
Opensecurity
  • Mobile Security Framework

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact