PT-2025-31984 · Maxthon · Maxthon3
CVE-2012-10032
·
Published
2012-12-05
·
Updated
2026-05-26
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Maxthon3 versions prior to 3.3
Description
Maxthon3 versions prior to 3.3 are vulnerable to cross context scripting (XCS) through the
about:history page. The browser’s trusted zone improperly handles injected script content, allowing attackers to execute arbitrary JavaScript in a privileged context. This flaw enables modification of browser configuration and execution of arbitrary code through Maxthon’s exposed DOM APIs, including maxthon.program.Program.launch() and maxthon.io.writeDataURL(). Exploitation requires user interaction, typically by visiting a malicious webpage that triggers the injection.Recommendations
Update Maxthon3 to version 3.3 or later.
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Maxthon3