CVE-2026-86550: UXSS vulnerability in ZTE browser products
Published Sep 8, 2026
·Updated
NuBrowser lacks protocol whitelist validation for the S.browserfallbackurl field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.
Affected Software
1 affected component
ZTE NuBrowser
Event History
Sep 8, 2026
CVE Published
via MITRE·08:14 AM
Data Sourced
via MITRE·08:14 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account or local access?
No. The vulnerability is remotely reachable and requires no privileges (AV:N/PR:N).
2
Is user interaction required for exploitation?
Yes. The attack vector indicates that user interaction is required (UI:R), such as causing a user to follow attacker-controlled content that triggers the vulnerable handling path.