CVE-2017-8936: Medium severity dolphin browser vulnerability
The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8936?
CVE-2017-8936 is considered a critical vulnerability as it allows man-in-the-middle attacks that can lead to the exposure of sensitive information.
How do I fix CVE-2017-8936?
To fix CVE-2017-8936, users should update the Dolphin Web Browser to version 9.23.3 or later, which addresses the SSL certificate verification issue.
Who is affected by CVE-2017-8936?
The vulnerability affects users of the Dolphin Web Browser, specifically versions 9.23.0 through 9.23.2 on iOS devices.
What can attackers do with CVE-2017-8936?
Attackers can exploit CVE-2017-8936 to perform man-in-the-middle attacks, allowing them to spoof SSL servers and intercept sensitive data.
Is there a workaround for CVE-2017-8936 if I cannot update?
While the best solution is to update the app, users can mitigate risks by using alternative browsers that properly validate SSL certificates.