An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted malicious webpage/URL, user may be tricked for a short period of time (until the page loads) to think content may be coming from a valid domain, while the content comes from the attacker controlled site.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-33305 An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted malicious webpage/URL, user may be tricked for a short period of time (until the page loads) to think content may be coming from a valid domain, while the content comes from the attacker controlled site.
Fixes

Solution

FIX: A fix has been released in the automatic update channel since 13th, April 2022. No user action is required.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: F-SecureUS

Published:

Updated: 2024-08-03T06:03:53.153Z

Reserved: 2022-04-08T00:00:00

Link: CVE-2022-28868

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-15T11:15:07.727

Modified: 2024-11-21T06:58:05.897

Link: CVE-2022-28868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses