CVE-2019-12366
Description
The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Nine Email 4.5.3a for Android allows XSS via event attributes and arbitrary file loading via src attributes when READ_EXTERNAL_STORAGE is granted.
Vulnerability
The Nine Email application through version 4.5.3a for Android is vulnerable to cross-site scripting (XSS) via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission [1]. This allows an attacker to inject malicious JavaScript into a WebView that may be used to access sensitive data or load files from external storage.
Exploitation
An attacker with network position to inject content (e.g., via a malicious email) can craft an email containing event attributes or src attributes that, when rendered in Nine's WebView, execute JavaScript. The user must have granted the READ_EXTERNAL_STORAGE permission, which is commonly requested by file attachment features [1]. No additional authentication is required beyond normal email access.
Impact
Successful exploitation allows an attacker to steal data from the WebView context, including email content and possibly files from external storage via the src attribute file loading. This can lead to information disclosure and potential privilege escalation if combined with other vulnerabilities [1].
Mitigation
No fixed version has been released as of the publication date (2020-03-18) and the vendor did not reply to the researcher [1]. Users should consider removing the READ_EXTERNAL_STORAGE permission via Android settings if the app still functions, or migrate to an alternative email client. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Nine/Nine applicationdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- release-notes.9folders.commitrex_refsource_MISC
- gubello.memitrex_refsource_MISC
- www.gubello.me/blog/javascript-injection-in-six-android-mail-clients/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.