An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted malicious webpage/URL, user may be tricked for a short period of time (until the page loads) to think content may be coming from a valid domain, while the content comes from the attacker controlled site.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33305 | An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted malicious webpage/URL, user may be tricked for a short period of time (until the page loads) to think content may be coming from a valid domain, while the content comes from the attacker controlled site. |
Fixes
Solution
FIX: A fix has been released in the automatic update channel since 13th, April 2022. No user action is required.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: F-SecureUS
Published:
Updated: 2024-08-03T06:03:53.153Z
Reserved: 2022-04-08T00:00:00
Link: CVE-2022-28868
No data.
Status : Modified
Published: 2022-04-15T11:15:07.727
Modified: 2024-11-21T06:58:05.897
Link: CVE-2022-28868
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD