An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can leverage this to perform address bar spoofing attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-20278 | An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can leverage this to perform address bar spoofing attack. |
Fixes
Solution
Upgrade to version 18.4.x or newer from Google Play
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: F-SecureUS
Published:
Updated: 2024-08-03T23:50:43.211Z
Reserved: 2021-05-27T00:00:00
Link: CVE-2021-33594
No data.
Status : Modified
Published: 2021-08-11T11:15:09.067
Modified: 2024-11-21T06:09:09.840
Link: CVE-2021-33594
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD