EN

critical CVE-2026-78997

UC Browser for Android (package com.UCMobile.intl: Cross-site scripting possible

NVD (NIST) reports one vulnerability in UC Browser for Android (package com.UCMobile.intl with severity critical. The stated impact is cross-site scripting. Affected: CVE-2026-78997. The full description, affected versions and recommended action are available from NVD (NIST).

CVSS
9.3

What this means for you

Attackers can run code in your users' browsers. This mainly affects publicly reachable portals and login forms, where sessions can be taken over.

Original source

NVD (NIST)

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.