Android browser vulnerable to Cross Application Scripting

"IBM researchers have found that it is possible for third party
applications to inject JavaScript code into instances of the Android
browser. According to a paper published by the researchers, the
vulnerability exists in Android 2.3.4 and 3.1 and is believed to exist
in earlier versions.

The bug behind the flaw, found in the Browser's onNewIntent() method, is
fixed in Android 2.3.5 and 3.2 and patches will be made available for
Android 2.2.x."

