Security Advisory
CVE-2019-0219
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.