CVE-2021-33594: F-Secure Safe browser for Android vulnerable to Address Bar Spoofing
An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can leverage this to perform address bar spoofing attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-33594?
CVE-2021-33594 is an address bar spoofing vulnerability discovered in Safe Browser for Android.
How does CVE-2021-33594 work?
When a user clicks on a specially crafted malicious URL, it appears as a legitimate one in the address bar while showing content from another domain in a separate window.
Which software is affected by CVE-2021-33594?
Safe Browser for Android versions up to 18.4.0 are affected by CVE-2021-33594.
What is the severity of CVE-2021-33594?
CVE-2021-33594 has a severity level of low (3.5).
How can I fix CVE-2021-33594?
To fix CVE-2021-33594, update Safe Browser for Android to a version above 18.4.0.