The default browser in Android versions older than 4.4 has a vulnerability that allows malicious websites to bypass a critical security mechanism. The issue is a universal cross-site scripting flaw that stems from how the browser handles javascript: strings preceded by a null byte character. The vulnerability was discovered by independent security researcher Rafay Baloch, who published a proof-of-concept exploit on his blog Aug. 31. The bug’s disclosure remained largely unnoticed until the Metasploit team developed a module that can be used to steal authentication cookies from users.”]

