A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main applications webview using a specially crafted gap-iab: URI.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cordova_inappbrowser | Apache | * | 3.0.0 (including) |