Security flaw found in Android browsers Dolphin & Mercury – Rotologix, a cybersecurity enthusiast, has identified zero-day flaws that could allow an attacker to perform remote code execution in two popular Android mobile browsers, Dolphin and Mercury, which count 100 million users.
The remote code execution exploit allows an attacker to replace the browser's theme package with a compromised one.
“Mercury Browser for Android suffers from an insecure intent to implement the URI system and a path traversal vulnerability in a custom web server used to support feature . Combining these vulnerabilities could allow a remote attacker to perform arbitrary reads and writes to files located within the Mercury Browser data directory,” the researcher wrote in a blog post.
It is said that the exploit by the attackers allows them to modify the download and application of new themes functions in the browser. Those affected must download and apply a new Dolphin browser theme again.
And for Dolphin, Rotologix says, “An attacker with the ability to control network traffic for Dolphin for Android users could modify the functionality of downloading and applying new themes for the browser. By exploiting this functionality, an attacker could achieve arbitrary file writing, which could then be turned into code execution in the browser content of the user’s device.”

