jigbrowser+ Application for Android contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the applications fail to properly implement the WebView class. This may allow a context-dependent attacker to use a specially crafted application to gain access to potentially sensitive information.
Classification
Location:
Context Dependent,
Mobile Phone / Hand-held Device
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to version 1.5.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.