First published: Thu Aug 05 2021(Updated: )
Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. Exploiting the vulnerability requires the user to click on a specially crafted, seemingly legitimate URL containing an embedded malicious redirect while using F-Secure Safe Browser for iOS.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Safe | <18.4.272901 |
Upgrade to version 18.4.x or newer from the App Store
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-33596 is medium with a score of 4.1.
CVE-2021-33596 allows an attacker to display a legitimate URL in the address bar while loading content from another domain, tricking users into believing it is from a legitimate source.
F-Secure Safe version 18.4.272901 on iPhone OS is affected by CVE-2021-33596.
Exploiting CVE-2021-33596 requires the user to click on a specially crafted URL that appears legitimate but contains a malicious payload.
Yes, you can find references for CVE-2021-33596 at the following links: 1. [F-Secure Vulnerability Reward Program](https://www.f-secure.com/en/business/programs/vulnerability-reward-program/hall-of-fame) 2. [F-Secure Security Advisories](https://www.f-secure.com/en/business/support-and-downloads/security-advisories) 3. [CVE-2021-33596 Security Advisory](https://www.f-secure.com/en/business/support-and-downloads/security-advisories/cve-2021-33596)