First published: Fri Dec 10 2021(Updated: )
A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a specially crafted seemingly legitimate URL SAFE browser goes into full screen and hides the user interface. A remote attacker can leverage this to perform spoofing attack.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Safe | <=17.9 |
FIX - Upgrade to version 18.5.x which is available in Google play.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-40834.
The severity of CVE-2021-40834 is medium with a severity value of 4.3.
When a user clicks on a specially crafted URL, the SAFE browser goes into full screen and hides the user interface, allowing a remote attacker to perform a spoofing attack.
Version 17.9 of F-secure SAFE Browser for Android is affected by CVE-2021-40834.
You can find more information about CVE-2021-40834 in the F-secure Vulnerability Reward Program Hall of Fame and the F-secure security advisories.