An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafted a malicious URL, if user does not carefully pay attention to url, user may be tricked to think content may be coming from a valid domain, while it comes from another. This is performed by using a very long username part of the url so that user cannot see the domain name. A remote attacker can leverage this to perform url address bar spoofing attack. The fix is, browser no longer shows the user name part in address bar.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-27992 | An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafted a malicious URL, if user does not carefully pay attention to url, user may be tricked to think content may be coming from a valid domain, while it comes from another. This is performed by using a very long username part of the url so that user cannot see the domain name. A remote attacker can leverage this to perform url address bar spoofing attack. The fix is, browser no longer shows the user name part in address bar. |
Fixes
Solution
Upgrade to version 18.5 or newer from the App Store
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: F-SecureUS
Published:
Updated: 2024-08-04T02:51:07.421Z
Reserved: 2021-09-09T00:00:00
Link: CVE-2021-40835
No data.
Status : Modified
Published: 2021-12-16T11:15:07.977
Modified: 2024-11-21T06:24:53.257
Link: CVE-2021-40835
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD