CVE-2021-25254: Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
Published May 21, 2025
·Updated
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
Affected Software
2 affected components
Yandex Yandex Browser Lite<21.1.0
Yandex Yandex Browser Android<21.1.0
Event History
May 21, 2025
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25254?
CVE-2021-25254 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2021-25254?
To fix CVE-2021-25254, update Yandex Browser Lite to version 21.1.0 or later.
3
What is the impact of CVE-2021-25254?
CVE-2021-25254 allows remote attackers to spoof the address bar, potentially leading to phishing attacks.
4
Which versions of Yandex Browser Lite are affected by CVE-2021-25254?
Yandex Browser Lite versions prior to 21.1.0 are affected by CVE-2021-25254.
5
Who is the vendor for CVE-2021-25254?
The vendor for CVE-2021-25254 is Yandex.