CVE-2021-44751: F-Secure SAFE Browser vulnerable to USSD attacks
A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can trigger dialer application from F-Secure browser which can be exploited by an attacker to send unwanted USSD messages or perform unwanted calls. In most modern Android OS, dialer application will require user interaction, however, some older Android OS may not need user interaction.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-44751?
CVE-2021-44751 is a vulnerability affecting F-Secure SAFE browser that allows an attacker to trigger the dialer application and send unwanted USSD messages or perform unwanted calls.
What is the severity of CVE-2021-44751?
CVE-2021-44751 has a severity of medium, with a CVSS score of 5.3.
How does CVE-2021-44751 work?
CVE-2021-44751 works by exploiting a maliciously crafted website attached with USSD code in JavaScript or iFrame, which triggers the dialer application of F-Secure SAFE browser.
How can CVE-2021-44751 be exploited?
CVE-2021-44751 can be exploited by an attacker by directing the victim to a malicious website containing the specially crafted USSD code.
Is there a fix for CVE-2021-44751?
Yes, F-Secure has provided a fix for CVE-2021-44751. It is recommended to update to the latest version of F-Secure SAFE browser to mitigate the vulnerability.