CVE-2012-4012: Cybozu Kunai

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.

Affected products

  • Cybozu Kunai: up to and including 2.0.5

Published 2012-09-08. Last modified 2026-06-16.