An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can leverage this to perform address bar spoofing attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-20278 An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can leverage this to perform address bar spoofing attack.
Fixes

Solution

Upgrade to version 18.4.x or newer from Google Play


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: F-SecureUS

Published:

Updated: 2024-08-03T23:50:43.211Z

Reserved: 2021-05-27T00:00:00

Link: CVE-2021-33594

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-11T11:15:09.067

Modified: 2024-11-21T06:09:09.840

Link: CVE-2021-33594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.