First published: Mon Jul 16 2012(Updated: )
The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Yahoo Yahoo\! Browser | <=1.2.0 | |
Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2645 is classified as a medium severity vulnerability due to its potential to allow remote attackers to access sensitive information.
To fix CVE-2012-2645, it is recommended to update the Yahoo! Browser application to version 1.3.0 or later.
CVE-2012-2645 specifically affects the Yahoo! Browser application version 1.2.0 and earlier for Android.
Yes, CVE-2012-2645 can be exploited remotely by attackers through a crafted application.
CVE-2012-2645 can potentially allow remote attackers to obtain sensitive information from the affected Android device.