CVE-2022-28868

3 documents3 sources
Severity
4.3MEDIUM
EPSS
0.3%
top 49.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateApr 16

Description

An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted malicious webpage/URL, user may be tricked for a short period of time (until the page loads) to think content may be coming from a valid domain, while the content comes from the attacker controlled site.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:LExploitability: 0.9 | Impact: 3.4

Affected Packages2 packages

NVDf-secure/safe18.6
CVEListV5f-secure/f-secure_mobile_security18.6All Version

🔴Vulnerability Details

2
GHSA
GHSA-96cc-vwgw-3gv7: An Address bar spoofing vulnerability was discovered in Safe Browser for Android2022-04-16
CVEList
Address Bar Spoofing Vulnerability in F-Secure SAFE Browser for Android2022-04-15
CVE-2022-28868 (MEDIUM CVSS 4.3) | An Address bar spoofing vulnerabili | cvebase.io