First published: Thu Mar 12 2020(Updated: )
Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several Unicode characters. The rendering mechanism, in conjunction with the "first strong character" concept, may improperly operate on a numerical IP address or an alphabetic string, leading to a spoofed URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opera Opera | =52.1.2517.139570 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12278 is a vulnerability in Opera through 53 on Android that allows Address Bar Spoofing.
The severity of CVE-2019-12278 is medium, with a CVSS score of 4.3.
CVE-2019-12278 affects Opera on Android by allowing characters from several languages to be displayed in Right-to-Left order, leading to Address Bar Spoofing.
To fix CVE-2019-12278, update Opera on your Android device to version 53 or later.
You can find more information about CVE-2019-12278 on the Opera Help website and a bug bounty write-up on Medium.