VYPR
Medium severity6.1NVD Advisory· Published Mar 18, 2020· Updated Jun 17, 2026

CVE-2019-12365

CVE-2019-12365

Description

The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:cloudmagic:newton:*:*:*:*:*:android:*:*
    Range: <=10.0.23
  • Newton/Newton applicationdescription
  • Newton/Newtonllm-fuzzy
    Range: <=10.0.23

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.