CVE-2021-44749: Universal Cross-Site Scripting Vulnerability in F-Secure SAFE Browser Protection for Android
A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-44749?
CVE-2021-44749 is a vulnerability affecting F-Secure SAFE browser protection that allows for universal cross-site scripting through browsing protection in a SAFE web browser.
How severe is this vulnerability?
The severity of CVE-2021-44749 is rated as critical with a CVSS score of 9.6.
Which software is affected by CVE-2021-44749?
F-Secure SAFE version 18.5 on Android is affected by CVE-2021-44749.
What is the Common Weakness Enumeration (CWE) category for this vulnerability?
The Common Weakness Enumeration (CWE) category for CVE-2021-44749 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
How can I fix CVE-2021-44749?
To fix CVE-2021-44749, ensure that you have updated F-Secure SAFE to the latest version provided by F-Secure.