CVE-2020-16873HighCVSS 4.7

Xamarin.Forms Spoofing Vulnerability

Published
September 8, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target system. For the attack to be successful, the targeted user would need to browse to a malicious website or a website serving the malicious code through Xamarin.Forms. The security update addresses this vulnerability by preventing the malicious Javascript from running in the WebView.

🎯 Affected products1

  • xamarin.forms

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (2)