---
id: CVE-2026-78997
title: >-
  UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314)
  contains a Universal Cross-Site Scripting vulnerability that allows an
  attacker to execute arbitrary JavaScript in the context of any origin
summary: >-
  UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314)
  contains a Universal Cross-Site Scripting vulnerability that allows an
  attacker to execute arbitrary JavaScript in the context of any origin. An
  attacker hosts a spe…
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T19:17:47.723'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78997'
references:
  - url: 'https://gist.github.com/OmriInbar-Novee/9fd65fe08c1b1cff6a19350e44425de2'
    label: cve@mitre.org
  - url: 'https://gist.github.com/OmriInbar-Novee/ef7a92db148b2eb1ab0aa7b99a565c4c'
    label: cve@mitre.org
  - url: 'https://gist.github.com/OmriInbar-Novee/9fd65fe08c1b1cff6a19350e44425de2'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T18:15:20.006490Z'
epss: 0.00399
epssPercentile: 0.31331
ingestedAt: '2026-09-08T19:08:49.674Z'
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/Hunt-Benito/the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss
  checkedAt: '2026-09-25T08:21:14.682Z'
---

## Overview

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain (via a reflected XSS) that leverages the browser's internal JavaScript bridge to register a deferred callback, navigate the tab to a victim site, and then execute attacker-controlled code on that site when a login dialog is dismissed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
