CVE-2021-44751

Severity
5.3MEDIUM
EPSS
0.3%
top 51.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMar 26

Description

A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS, dialer application will require user interaction, however, some older Android OS may not need user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:LExploitability: 0.9 | Impact: 3.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-7gxq-69xx-2vr4: A vulnerability affecting F-Secure SAFE browser was discovered2022-03-26
CVEList
F-Secure SAFE Browser vulnerable to USSD attacks2022-03-25
CVE-2021-44751 (MEDIUM CVSS 5.3) | A vulnerability affecting F-Secure | cvebase.io