CVE-2017-17551: Input Validation
The Backup and Restore feature in Mobotap Dolphin Browser for Android 12.0.2 suffers from an arbitrary file write vulnerability when attempting to restore browser settings from a malicious Dolphin Browser backup file. This arbitrary file write vulnerability allows an attacker to overwrite a specific executable in the Dolphin Browser's data directory with a crafted malicious executable. Every time the Dolphin Browser is launched, it will attempt to run the malicious executable from disk, thus executing the attacker's code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17551?
CVE-2017-17551 is classified as a high severity vulnerability due to the potential impact of arbitrary file writes.
How do I fix CVE-2017-17551?
To fix CVE-2017-17551, users should update the Dolphin Browser to a patched version that addresses the arbitrary file write vulnerability.
What type of vulnerability is CVE-2017-17551?
CVE-2017-17551 is an arbitrary file write vulnerability affecting the Backup and Restore feature in Dolphin Browser.
What software is affected by CVE-2017-17551?
CVE-2017-17551 affects version 12.0.2 of the Dolphin Browser for Android.
What can an attacker do with CVE-2017-17551?
An attacker can exploit CVE-2017-17551 to overwrite files on a victim's device by using a malicious backup file.