First published: Fri Apr 15 2022(Updated: )
An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted malicious webpage/URL, user may be tricked for a short period of time (until the page loads) to think content may be coming from a valid domain, while the content comes from the attacker controlled site.
Credit: cve-notifications-us@f-secure.com
Affected Software | Affected Version | How to fix |
---|---|---|
F-secure Safe | <=18.6 |
FIX: A fix has been released in the automatic update channel since 13th, April 2022. No user action is required.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28868 is an address bar spoofing vulnerability in Safe Browser for Android.
When a user clicks on a specially crafted malicious webpage/URL, the user may be tricked into thinking that the content is coming from a valid domain, while it actually comes from a malicious source.
CVE-2022-28868 has a severity rating of 4.3 out of 10, which is classified as medium severity.
Version 18.6 of F-secure Safe for Android is affected by CVE-2022-28868.
To fix CVE-2022-28868, it is recommended to update to a patched version of F-secure Safe for Android.