CVE-2021-33594

3 documents3 sources
Severity
3.5LOW
EPSS
0.3%
top 46.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateMay 24

Description

An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can leverage this to perform address bar spoofing attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages2 packages

NVDf-secure/safe< 18.4.0
CVEListV5f-secure/f-secure_mobile_security18.4x18.3x*

🔴Vulnerability Details

2
GHSA
GHSA-w9rw-g2g4-x27x: An address bar spoofing vulnerability was discovered in Safe Browser for Android2022-05-24
CVEList
F-Secure Safe browser for Android vulnerable to Address Bar Spoofing2021-08-11