CVE-2026-86550 - UXSS vulnerability in ZTE browser products
Brief
CVE ID : CVE-2026-86550
Published : Sept. 8, 2026, 9:18 a. m.
- 1 hour, 31 minutes ago
Description : NuBrowser lacks protocol whitelist validation for the S. browser_fallback_url field of intent://, allowing attackers to inject URLs via 302 redirects. This results in a universal cross‑site scripting (UXSS) vulnerability that enables script execution within the origin of arbitrary websites.
Severity: 6.5
- MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
