First published: Sun Mar 06 2022(Updated: )
A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to cause universal cross-site scripting through browsing protection in a SAFE web browser. User interaction is required prior to exploitation. A successful exploitation may lead to arbitrary code execution.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Safe | =18.5 |
FIX : A fix has been released in the automatic update channel since 18th February 2022. No user action is required if automatic update is enabled.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44749 is a vulnerability affecting F-Secure SAFE browser protection that allows for universal cross-site scripting through browsing protection in a SAFE web browser.
The severity of CVE-2021-44749 is rated as critical with a CVSS score of 9.6.
F-Secure SAFE version 18.5 on Android is affected by CVE-2021-44749.
The Common Weakness Enumeration (CWE) category for CVE-2021-44749 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2021-44749, ensure that you have updated F-Secure SAFE to the latest version provided by F-Secure.