Sleipnir Mobile for Android loads arbitrary Extension API


Sleipnir Mobile for Android has an Extension mechanism to customize browser functions, and this Extension function makes calls to an Extension API.
Sleipnir Mobile for Android contains an issue that may allow a specially crafted web page to load an arbitrary Extension API.

Keita Haga of keitahaga.com reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: High
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products

Fenrir Inc.
  • Sleipnir Mobile for Android 2.8.0 and earlier
  • Sleipnir Mobile for Android Black Edition 2.8.0 and earlier


If a user accesses a malicious URL, an attacker may cause an unintended file download, or obtain information of the HTTP response body for a site that has been logged into using Sleipnir Mobile for Android.

[Update the software]
Update to the latest version according to the information provided by the developer.
Vendor Information

Fenrir Inc.
CWE (What is CWE?)

  1. Permissions(CWE-264) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2013-2304

  1. JVN : JVN#02895867
  2. National Vulnerability Database (NVD) : CVE-2013-2304
Revision History

  • [2013/04/12]
      Web page was published