A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage this to perform spoofing attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-27991 A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage this to perform spoofing attack.
Fixes

Solution

FIX - Upgrade to version 18.5.x which is available in Google play.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: F-SecureUS

Published:

Updated: 2024-08-04T02:51:07.506Z

Reserved: 2021-09-09T00:00:00

Link: CVE-2021-40834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-10T14:15:10.093

Modified: 2024-11-21T06:24:53.117

Link: CVE-2021-40834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.