A serious flaw vulnerability has been discovered in the default browser on a large number of Android devices that allows to bypass the Same Origin Policy. The vulnerability CVE-2014-6041 affects Android versions 4.2.1 and all older versions. The latest release, Android 4.4, is not affected by the flaw, but the new version of the popular mobile OS is installed only on 25 percent of the devices. A further element of concern is the availability of a specific Metasploit module which allows easily to exploit the vulnerability.”]
Source: https://securityaffairs.co/wordpress/28381/hacking/android-flaw-same-origin-policy.html